iT邦幫忙

2026 iThome 鐵人賽

DAY 8
0
Security

Like an Exploition:IoT 韌體漏洞鍊成術系列 第 8 篇

【𝕯𝖆𝖞 𝟖】CVE-2025-25634 (1/2)

  • 分享至 

  • xImage
  •  

前言

今天繼續來漏洞復現,沿用前面一個案例的設備和 firmware 版本,然後這次來復現跟 memory 相關的漏洞。Tenda 你怎麼一堆洞QQ

CVE-2025-25634

0x01 Target Vulnerability

/goform/GetParentControlInfo 的 handler

server 沒有強制 mac 必須真的是 MAC address,也沒有在 strcpy 前限制長度。
參數會在 GetParentControlInfo 注入,造成Stack Buffer Overflow
image.png

image.png

Stack buffer s (0x254 bytes)

s+0   ┌──────────────┐
      │ other field? │
s+2   ├──────────────┤ ← strcpy start
      │ AA:BB:CC:... │
      │              │
      │              │
      ├──────────────┤ ← s + 0x254,buffer end
      │ stack data   │
      │ saved regs   │
      │ ...          │
      └──────────────┘

0x02 BOF 實踐

由於因此只要注入一個 > 0x254 (>596 bytes) 的值進入就可以達成 buffer overflow 造成 segmentation fault

GET /goform/GetParentControlInfo?mac=AAAA...<snip 596 bytes>%EF%BE%AD%DE HTTP/1.1

0x03 POC

我的QEMU跟kali 鼠掉兩天了 希望等等可已修好QQ
GET /goform/GetParentControlInfo?mac=AAAA...%EF%BE%AD%DE HTTP/1.1


上一篇
【𝕯𝖆𝖞 𝟕】My First CVE (Reproduction) - Web Command Injeciton (2/2)
下一篇
【𝕯𝖆𝖞 𝟗】CVE-2025-25634 (2/2)
系列文
Like an Exploition:IoT 韌體漏洞鍊成術 共 18 篇
圖片
  熱門推薦
圖片
{{ item.channelVendor }} | {{ item.webinarstarted }} |
{{ formatDate(item.duration) }}
直播中

尚未有邦友留言

立即登入留言