Hack The Emulated Planet: Vulnerability Hunting on Planet WGS-804HPT Industrial Switches
ID: 2748abba-0e6d-5b44-a142-c6442a82fa7c
STIX ID: report--2748abba-0e6d-5b44-a142-c6442a82fa7c
Feed Name: Claroty Team82
This blog describes Team82's discovery of three vulnerabilities in the Planet WGS-804HPT industrial switch—including a pre-auth stack-buffer overflow in dispatcher.cgi and an OS command injection—that allow unauthenticated remote code execution. The authors explain firmware extraction, using binwalk and QEMU user/system emulation to recreate the device environment, static analysis of the Boa-based web service, remote debugging, exploit development (including MIPS shellcode) and a working PoC; the vendor was privately notified and released a firmware update.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
