{"id":19236451,"url":"https://github.com/infobyte/cve-2022-27255","last_synced_at":"2025-04-07T19:16:21.223Z","repository":{"id":56773241,"uuid":"511232241","full_name":"infobyte/cve-2022-27255","owner":"infobyte","description":null,"archived":false,"fork":false,"pushed_at":"2022-08-30T13:23:51.000Z","size":29003,"stargazers_count":275,"open_issues_count":2,"forks_count":51,"subscribers_count":16,"default_branch":"main","last_synced_at":"2025-03-31T16:19:09.505Z","etag":null,"topics":[],"latest_commit_sha":null,"homepage":null,"language":"Python","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/infobyte.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null}},"created_at":"2022-07-06T17:29:04.000Z","updated_at":"2025-02-14T17:11:11.000Z","dependencies_parsed_at":"2022-08-16T02:30:51.000Z","dependency_job_id":null,"html_url":"https://github.com/infobyte/cve-2022-27255","commit_stats":null,"previous_names":[],"tags_count":0,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/infobyte%2Fcve-2022-27255","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/infobyte%2Fcve-2022-27255/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/infobyte%2Fcve-2022-27255/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/infobyte%2Fcve-2022-27255/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/infobyte","download_url":"https://codeload.github.com/infobyte/cve-2022-27255/tar.gz/refs/heads/main","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247713258,"owners_count":20983683,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":[],"created_at":"2024-11-09T16:20:39.087Z","updated_at":"2025-04-07T19:16:21.197Z","avatar_url":"https://github.com/infobyte.png","language":"Python","funding_links":[],"categories":[],"sub_categories":[],"readme":"# CVE-2022-27255 - Realtek eCos SDK SIP ALG buffer overflow \n\nThis repository contains the materials for the talk \"Exploring the hidden attack surface of OEM IoT devices: pwning thousands of routers with a vulnerability in Realtek’s SDK for eCos OS.\", which was presented at [DEFCON30](https://forum.defcon.org/node/241835). \n\nThe contents of this repo include:\n\n- `analysis`: Automated firmware analysis to detect the presence of CVE-2022-27255 (Run `analyse_firmware.py`).\n- `exploits_nexxt`: PoC and exploit code. The PoC should work on every affected router, however the exploit code is specific for the Nexxt Nebula 300 Plus router.\n- `ghidra_scripts`: Vulnerable function call searching script and CVE-2022-27255 detection script.\n- `DEFCON`: Slide deck \u0026 poc video.\n\n## Vulnerable devices:\n\n- Nexxt Nebula 300 Plus\n- Tenda F6 V5.0\n- Tenda F3 V3\n- Tenda F9 V2.0\n- Tenda AC5 V3.0\n- Tenda AC6 V5.0\n- Tenda AC7 V4.0\n- Tenda A9 V3\n- Tenda AC8 V2.0\n- Tenda AC10 V3\n- Tenda AC11 V2.0\n- Tenda FH456 V4.0\n- Zyxel NBG6615 V1.00\n- Intelbras RF 301K V1.1.15\n- Multilaser AC1200 RE018\n- iBall 300M-MIMO (iB-WRB303N)\n- Brostrend AC1200 extender\n- MT-Link MT-WR850N\n- MT-Link MT-WR950N\n- Everest EWR-301\n- D-Link DIR-822 h/w version B\n- Speedefy K4\n- Ultra-Link Wireless N300 Universal Range Extender\n- Keo KLR 301\n- QPCOM QP-WR347N\n- NEXT 504N\n- Nisuta NS-WIR303N (probably V2)\n- Rockspace AC2100 Dual Band Wi-Fi Range Extender\n- KNUP KP-R04\n- Hikvision DS-3WR12-E\n\nIf you find a new vulnerable device, please submit a pull request.\n\n## Acknowledgements\n\n- Octavio Gianatiempo (@ogianatiempo).\n- Octavio Galland (@GallandOctavio)\n- Javier Aguinaga (@pastaCLS)\n- Emilio Couto (@ekio_jp)\n\n## Corrections:\n- @munchkindev\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Finfobyte%2Fcve-2022-27255","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Finfobyte%2Fcve-2022-27255","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Finfobyte%2Fcve-2022-27255/lists"}