Fixed version information

This commit is contained in:
Damian Pfammatter
2024-07-11 08:22:40 +02:00
parent 61af139ec6
commit f6fa1306f0
3 changed files with 4 additions and 3 deletions
+2 -1
View File
@@ -8,7 +8,8 @@ This repository is intended to demonstrate some functionalities of
**symbolic execution** on real-world (ARMv7) binaries. We show some of
[Morion](https://github.com/pdamian/morion)'s capabilities by giving a concrete example, namely, how
it can assist during the process of creating a working **exploit for CVE-2022-27646** - a stack
buffer overflow vulnerability in NETGEAR R6700v3 routers (version 10.04.120_10.0.91).
buffer overflow vulnerability in NETGEAR R6700v3 routers (affected version 1.0.4.120_10.0.91, fixed
in later versions).
The repository contains all **files** (under [firmware](./firmware/), [libcircled](./libcircled/),
[morion](./morion/) and [server](./server/)) needed to follow along (e.g. scripts to emulate the
+1 -1
View File
@@ -17,7 +17,7 @@
# Emulation
In this chapter, we briefly mention a handful of **files** and **scripts** that can be used to
emulate the intended target, the binary *circled* from NETGEAR R6700v3 routers (firmware version
10.04.120_10.0.91). For each of these files, a brief explanation of its purpose is provided.
1.0.4.120_10.0.91). For each of these files, a brief explanation of its purpose is provided.
**Note**: While not identical, our emulation was inspired by
[Emulating, Debugging and Exploiting NETGEAR R6700v3 cicled Binary](https://medium.com/@INTfinity/1-1-emulating-netgear-r6700v3-circled-binary-cve-2022-27644-cve-2022-27646-part-1-5bab391c91f2).
+1 -1
View File
@@ -20,7 +20,7 @@ direct the interested reader to the original writeup by the vulnerability discov
## Description
[CVE-2022-27646](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27646) corresponds to a
pre-authentication **remote code execution (RCE)** vulnerability in NETGEAR R6700v3 routers
(version 10.04.120_10.0.91) that might be exploited over the WAN interface.
(version 1.0.4.120_10.0.91) that might be exploited over the WAN interface.
The vulnerability resides in a binary `/bin/circled`, which occasionally fetches a file named
`circleinfo.txt` from a remote web server. During parsing of the downloaded file, a **stack buffer