7.5
CVSSv3

CVE-2017-16902

Published: 20/11/2017 Updated: 12/12/2017
CVSS v2 Base Score: 7.8 | Impact Score: 6.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 785
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:C

Vulnerability Summary

On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.

Vulnerable Product Search on Vulmon Subscribe to Product

vonage vdv-23_firmware 3.2.11-0.9.40

Exploits

Overview During an evaluation of the Vonage home phone router, it was identified that the loginUsername and loginPassword parameters were vulnerable to a buffer overflow This overflow caused the router to crash and reboot Further analysis will be performed to find out if the the crash is controllable and allow for full remote code execution Dev ...