NetUSB, IoT and Supply Chain Risk
ID: de156ca2-5ea2-552f-9393-3286153adaef
STIX ID: report--de156ca2-5ea2-552f-9393-3286153adaef
Feed Name: Security Ledger
NetUSB, a widely used USB-over-IP component by KCodes found in routers and embedded devices from many vendors, contains a remotely exploitable kernel stack buffer overflow triggered by an overlong “computer name.” The flaw can cause memory corruption leading to denial-of-service or potentially arbitrary remote code execution; the NetUSB service often runs by default on TCP port 20005, some devices expose that port to the Internet, and static AES keys in firmware and clients weaken authentication—SEC Consult developed a PoC but has not publicly released a working exploit.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
