module

Linksys WRT120N tmUnblock Stack Buffer Overflow

Disclosed
Feb 19, 2014
Created
May 30, 2018

Description

This module exploits a stack-based buffer overflow vulnerability in the WRT120N Linksys router
to reset the password of the management interface temporarily to an empty value.
This module has been tested successfully on a WRT120N device with firmware version
1.0.07.

Authors

Craig Heffner
Michael Messner [email protected]

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/admin/http/linksys_tmunblock_admin_reset_bof
msf auxiliary(linksys_tmunblock_admin_reset_bof) > show actions
...actions...
msf auxiliary(linksys_tmunblock_admin_reset_bof) > set ACTION < action-name >
msf auxiliary(linksys_tmunblock_admin_reset_bof) > show options
...show and set options...
msf auxiliary(linksys_tmunblock_admin_reset_bof) > run

Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.