CVE-2017-18046: Buffer Overflow
Buffer overflow on Dasan GPON ONT WiFi Router H640X 12.02-01121 2.77p1-1124 and 3.03p2-1146 devices allows remote attackers to execute arbitrary code via a long POST request to the loginaction function in /cgi-bin/loginaction.cgi (aka cgipage.cgi).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-18046?
CVE-2017-18046 is considered a high severity vulnerability due to its potential for remote code execution.
How do I fix CVE-2017-18046?
To mitigate CVE-2017-18046, update the firmware of the Dasan GPON ONT WiFi Router H640X to a version that does not contain the buffer overflow vulnerability.
What devices are affected by CVE-2017-18046?
CVE-2017-18046 affects Dasan GPON ONT WiFi Router H640X devices running firmware versions 2.77p1-1124, 3.03p2-1146, and 12.02-01121.
What type of attack does CVE-2017-18046 exploit?
CVE-2017-18046 can be exploited through a long POST request to the login_action function in the router's CGI scripts.
Is there any workaround for CVE-2017-18046 until a fix is available?
A practical workaround for CVE-2017-18046 includes disabling remote management features on the Dasan GPON ONT WiFi Router H640X.