mirror of
https://github.com/cyber-defence-campus/netgear_r6700v3_circled
synced 2026-08-09 12:29:06 +00:00
Fixed version information
This commit is contained in:
@@ -8,7 +8,8 @@ This repository is intended to demonstrate some functionalities of
|
||||
**symbolic execution** on real-world (ARMv7) binaries. We show some of
|
||||
[Morion](https://github.com/pdamian/morion)'s capabilities by giving a concrete example, namely, how
|
||||
it can assist during the process of creating a working **exploit for CVE-2022-27646** - a stack
|
||||
buffer overflow vulnerability in NETGEAR R6700v3 routers (version 10.04.120_10.0.91).
|
||||
buffer overflow vulnerability in NETGEAR R6700v3 routers (affected version 1.0.4.120_10.0.91, fixed
|
||||
in later versions).
|
||||
|
||||
The repository contains all **files** (under [firmware](./firmware/), [libcircled](./libcircled/),
|
||||
[morion](./morion/) and [server](./server/)) needed to follow along (e.g. scripts to emulate the
|
||||
|
||||
+1
-1
@@ -17,7 +17,7 @@
|
||||
# Emulation
|
||||
In this chapter, we briefly mention a handful of **files** and **scripts** that can be used to
|
||||
emulate the intended target, the binary *circled* from NETGEAR R6700v3 routers (firmware version
|
||||
10.04.120_10.0.91). For each of these files, a brief explanation of its purpose is provided.
|
||||
1.0.4.120_10.0.91). For each of these files, a brief explanation of its purpose is provided.
|
||||
|
||||
**Note**: While not identical, our emulation was inspired by
|
||||
[Emulating, Debugging and Exploiting NETGEAR R6700v3 cicled Binary](https://medium.com/@INTfinity/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2).
|
||||
|
||||
@@ -20,7 +20,7 @@ direct the interested reader to the original writeup by the vulnerability discov
|
||||
## Description
|
||||
[CVE-2022-27646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27646) corresponds to a
|
||||
pre-authentication **remote code execution (RCE)** vulnerability in NETGEAR R6700v3 routers
|
||||
(version 10.04.120_10.0.91) that might be exploited over the WAN interface.
|
||||
(version 1.0.4.120_10.0.91) that might be exploited over the WAN interface.
|
||||
|
||||
The vulnerability resides in a binary `/bin/circled`, which occasionally fetches a file named
|
||||
`circleinfo.txt` from a remote web server. During parsing of the downloaded file, a **stack buffer
|
||||
|
||||
Reference in New Issue
Block a user