IoT & Hardware

Memory Corruption

Trendnet wireless camera buffer overflow vulneribility

TrendNet wireless camera buffer overflow vulneribility TrendNet ProView Wireless camera TV-IP512WN (version v1.0R) is vulnerable to buffer overflow in handling RTSP packet in firmware version 1.0.4…

9.8
/ 10
Critical
CVSS v3.1
ADVISORY ID
PS33
PUBLISHED
2022-10-03
CVE IDs
CVE-2020-12763
VENDORS
TRENDnet
PUBLIC EXPLOIT
PoC public
CWE
CWE-787
PRODUCT
ProView Wireless camera TV-IP512WN
CVSS VECTOR
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Abstract blurred background with dark tones and smooth gradient waves of blue, purple, and orange hues.
Summary

Overview

TrendNet wireless camera buffer overflow vulneribility

TrendNet ProView Wireless camera TV-IP512WN (version v1.0R) is vulnerable to buffer overflow in handling RTSP packet in firmware version 1.0.4 which may result in remote code execution or denial of service. The issue is in the binary rtspd which resides in /sbin folder which is responsible for serving rtsp connection received by the device. The problem arises in parsing “Authorization: Basic” RTSP header which could be arbitrarily long, the value of this header is copied onto stack memory without any bounds check which could lead to a buffer overflow. What makes this vulnerability more severe is that the user need not be authenticated to trigger the overflow.

Vulnerability details

Vulnerability details

CVE-2020-12763
CWE-787
Critical | 9.8

TrendNet wireless camera buffer overflow vulneribility TrendNet ProView Wireless camera TV-IP512WN (version v1.0R) is vulnerable to buffer overflow in handling RTSP packet in firmware version 1.0.4 which may result in remote code execution or denial of

Auth:
None (remote)
Impact:
Sensitive data disclosure, arbitrary data or code modification, denial of service
DISCLOSURE

Disclosure timeline

2020-01-13 Report the issue to the vendor

2020-01-14 Vendor responded they provide fix for product has reached End-of-Life

2020-01-15 Informed the vendor that if they don’t fix the issue in 90 days we will publish the full disclosure unless they responded otherwise

2020-03-18 Requested CVE ID for the vulnerability

2020-03-18 Vendor responded they don’t verify the vulnerability which has reached EOF

2020-05-09 Requested Program Root CNA for CVE ID

2020-05-10 CVE ID Reserved

2020-05-11 Published the full disclosure

References

Credits

Munawwar Hussain Shelia