Remote Code Execution Vulnerability in HooToo Trip Mate 6 (TM6) Firmware 2.000.030 and Earlier

Remote Code Execution Vulnerability in HooToo Trip Mate 6 (TM6) Firmware 2.000.030 and Earlier

CVE-2017-9026 · HIGH Severity

AV:N/AC:L/AU:N/C:P/I:P/A:P

Stack buffer overflow in vshttpd (aka ioos) in HooToo Trip Mate 6 (TM6) firmware 2.000.030 and earlier allows remote unauthenticated attackers to control the program counter via a specially crafted fname parameter of a GET request.

Learn more about our Web Application Penetration Testing UK.