USRobotics Broadband-Router GET Request DoS Vulnerability
BID:6994
Info
USRobotics Broadband-Router GET Request DoS Vulnerability
| Bugtraq ID: | 6994 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 28 2003 12:00AM |
| Updated: | Feb 28 2003 12:00AM |
| Credit: | Discovery of this vulnerability has been credited to xti <[email protected]>. |
| Vulnerable: |
U.S.Robotics Broadband-Router 8000A/8000-2 2.5 |
| Not Vulnerable: | |
Discussion
USRobotics Broadband-Router GET Request DoS Vulnerability
USRobotics Broadband-Routers are reportedly prone to denial of service attacks. An attacker can exploit this vulnerability by issuing an overly long GET request to the embedded web server of a vulnerable USRobotics device. When the device attempts to process the malformed input, it will crash. It has been reported that this condition may be reproduced from within the internal network.
This condition may be due to a buffer overflow. This issue is reported to affect v2.5 of US Robotics Broadband-Router 8000A/8000-2 (USR848000A-02).
USRobotics Broadband-Routers are reportedly prone to denial of service attacks. An attacker can exploit this vulnerability by issuing an overly long GET request to the embedded web server of a vulnerable USRobotics device. When the device attempts to process the malformed input, it will crash. It has been reported that this condition may be reproduced from within the internal network.
This condition may be due to a buffer overflow. This issue is reported to affect v2.5 of US Robotics Broadband-Router 8000A/8000-2 (USR848000A-02).
Exploit / POC
USRobotics Broadband-Router GET Request DoS Vulnerability
There is no exploit needed.
There is no exploit needed.