Telus Actiontec WEB6000Q Denial Of Service
Posted by deepcore on June 13, 2019 – 11:59 am
Telus Actiontec WEB6000Q with firmware 1.1.02.22 suffers from a denial of service vulnerability. By querying CGI endpoints with empty (GET/POST/HEAD) requests causes a Segmentation Fault of the uhttpd webserver. Since there is no watchdog on this daemon, a device reboot is needed to restart the webserver to make any modification to the device.
Post a reply
You must be logged in to post a comment.