#VU11222 Stack-based buffer overflow in AsusWRT - CVE-2017-12754
Published: March 22, 2018
AsusWRT
Asus
Description
The vulnerability allows a remote authenticated attacker to execute arbitrary code on the target system.
The weakness exists in the httpd daemon due to improper processing of crafted HTTP GET request packets. A remote attacker can send a specially crafted HTTP GET request that contains a long delete_offline_client parameter, trigger a stack-based buffer overflow and execute arbitrary code.