Pwn2Own: WAN-to-LAN Exploit Showcase, Part 1
ID: e23ac281-a828-5daf-93c4-13dde44ff179
STIX ID: report--e23ac281-a828-5daf-93c4-13dde44ff179
Feed Name: Claroty Team82
Date Published: 2024-07-15
Date Updated: 2026-04-17
Author: Sharon Brizinov; Noam Moshe; Tomer Goldschmidt
This research describes a WAN-to-LAN exploit chain against TP-Link ER605 routers discovered at Pwn2Own Toronto 2023: a Comexe DDNS protocol authentication weakness, a stack-based overflow in cmxddnsd permitting RCE, and an out-of-bounds read used to bypass ASLR. The authors demonstrate achieving remote root on the router, opening firewall rules and proxying to pivot to a Synology BC500 IP camera, and note that vendors (TP-Link and Synology) released firmware fixes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
