Buffalo TeraStation Multiple Security Vulnerabilities
BID:57634
Info
Buffalo TeraStation Multiple Security Vulnerabilities
| Bugtraq ID: | 57634 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2013 12:00AM |
| Updated: | Jan 30 2013 12:00AM |
| Credit: | Andrea Fabrizi |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Buffalo TeraStation Multiple Security Vulnerabilities
Buffalo TeraStation is prone to an arbitrary file download and an arbitrary command-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these issues to download arbitrary files and execute arbitrary-commands with root privilege within the context of the vulnerable system. Successful exploits will result in the complete compromise of affected system.
Buffalo TeraStation is prone to an arbitrary file download and an arbitrary command-injection vulnerability because it fails to sufficiently sanitize user-supplied data.
An attacker can exploit these issues to download arbitrary files and execute arbitrary-commands with root privilege within the context of the vulnerable system. Successful exploits will result in the complete compromise of affected system.
Exploit / POC
Buffalo TeraStation Multiple Security Vulnerabilities
Attackers can use a browser to exploit this issue.
The following example data is available:
Attackers can use a browser to exploit this issue.
The following example data is available:
Solution / Fix
Buffalo TeraStation Multiple Security Vulnerabilities
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Buffalo TeraStation Multiple Security Vulnerabilities
References:
References:
- TeraStation Homepage (Buffalotech)