#VU24232 Buffer overflow in F@st 3890 and F@st 3686 - CVE-2019-19494

 

#VU24232 Buffer overflow in F@st 3890 and F@st 3686 - CVE-2019-19494

Published: January 14, 2020 / Updated: April 1, 2020


Vulnerability identifier: #VU24232
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2019-19494
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: Public exploit is available
Vulnerable software:
F@st 3890
F@st 3686
Software vendor:
Sagemcom

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error when processing packets sent to spectrum analyzer build-in feature. By default the affected router accepts requests from local network only, however an attacker can craft a specially crafted webpage and use victim's browser to deliver malicious request to the affected router, e.g. via websockets and a specially crafted JSON payload.

Successful exploitation of this vulnerability may result in complete compromise of the affected router.

Note, this vulnerability was dubbed Cable Haunt by the researcher.


Remediation

Install updates from vendor's website.

External links