Heap Buffer Overflow in vshttpd Allows Remote Code Execution

Heap Buffer Overflow in vshttpd Allows Remote Code Execution

CVE-2017-9025 · MEDIUM Severity

AV:N/AC:L/AU:N/C:N/I:P/A:P

Heap buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted HTTP Cookie header.

Learn more about our Web Application Penetration Testing UK.