An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent...
Vulnerability Description
An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-19524
Credits & Attribution
No credits recorded in the NVD database.
References
- https://seclists.org/bugtraq/2019/Feb/21
- https://www.exploit-db.com/exploits/46358/
- https://s3curityb3ast.github.io/KSA-Dev-001.md
- http://packetstormsecurity.com/files/151608/Skyworth-GPON-HomeGateways-Optical-Network-Stack-Overflow.html
- http://seclists.org/fulldisclosure/2019/Feb/30
- https://www.breakthesec.com/2019/02/cve-2018-19524-stack-overflow-in.html
More from skyworthdigital
View All →Affected Vendor
skyworthdigital
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.