vendor:
Mongoose
by:
nion
9
CVSS
CRITICAL
Remote Code Execution
119
CWE
Product Name: Mongoose
Affected Version From: shttpd <= 1.42, mongoose <= 3.0
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2011-2900
CPE: a:mongoose:mongoose:3.0
Platforms Tested: Linux (proprietary embedded distro) Linux 2.6.18-ubi-sys-V2.0.17
2011
Remote root on sfr/ubiquisys femtocell webserver (wsal/shttpd/mongoose)
This exploit allows an attacker to gain remote root access on the sfr/ubiquisys femtocell webserver. It takes advantage of a vulnerability in the shttpd and mongoose software versions <= 1.42 and <= 3.0 respectively. By sending a specially crafted PUT request, the attacker can overwrite the program counter (pc) and execute arbitrary code. The exploit includes stack lifting techniques to bypass security measures and achieve the desired outcome.
Mitigation:
To mitigate this vulnerability, it is recommended to update the shttpd and mongoose software to versions higher than 1.42 and 3.0 respectively. Additionally, implementing proper input validation and sanitization techniques can help prevent similar attacks.