ASUS B1M projector remote commands...

- AV AC AU C I A
发布: 2025-04-13
修订: 2025-04-13

We recently obtained a ASUS B1M projector[0] and have been exploring its capabilities when we discovered trivial to exploit vulnerabilities. The ASUS B1M features a small Wi-Fi adapter for a direct wireless connection to a notebook PC, or Android and iOS devices. The projector comes with an embedded MIPS computer running Linux that can be used for streaming your desktop or mobile device similar to miracast using a USB wifi adapter. We discovered that the web service used by the projector is prone to command injection vulnerabilities, buffer overflows and the usual security mishaps made in embedded devices. The thttpd 2.25b web server runs by default on 192.168.111.1 and is accessible when a client connects to the device in access point mode. It is possible to inject commands into the embedded webserver of the projector which of course is running with full “root” privileges. The response of the commands can be echo’d back to the user by manipulating parameters to a CGI script as...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息