CVE-2015-2797

Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execute arbitrary code via a long string in the redirect parameter to cgi-bin/login.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:airties:air_firmware:*:*:*:*:*:*:*:*
OR cpe:2.3:h:airties:air_5021:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5341:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5342:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5343:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5442:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5443:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5444tt:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5453:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5650tt:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5750:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_5760:-:*:*:*:*:*:*:*
cpe:2.3:h:airties:air_6372:-:*:*:*:*:*:*:*

History

21 Nov 2024, 02:28

Type Values Removed Values Added
References () http://osvdb.org/show/osvdb/120335 - () http://osvdb.org/show/osvdb/120335 -
References () http://www.bmicrosystems.com/blog/exploiting-the-airties-air-series/ - Exploit () http://www.bmicrosystems.com/blog/exploiting-the-airties-air-series/ - Exploit
References () http://www.securityfocus.com/bid/75355 - () http://www.securityfocus.com/bid/75355 -
References () https://www.exploit-db.com/exploits/36577/ - Exploit () https://www.exploit-db.com/exploits/36577/ - Exploit
References () https://www.exploit-db.com/exploits/37170/ - Exploit () https://www.exploit-db.com/exploits/37170/ - Exploit

Information

Published : 2015-06-19 14:59

Updated : 2024-11-21 02:28


NVD link : CVE-2015-2797

Mitre link : CVE-2015-2797

CVE.ORG link : CVE-2015-2797


JSON object : View

Products Affected

airties

  • air_5343
  • air_5750
  • air_5342
  • air_5444tt
  • air_5453
  • air_5650tt
  • air_5760
  • air_5442
  • air_5443
  • air_6372
  • air_firmware
  • air_5341
  • air_5021
CWE
CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer