D-Link EyeOn Baby Monitor (DCS-825L) Remote Code Execution

D-Link EyeOn Baby Monitor (DCS-825L) suffers from a remote code execution vulnerability.

Reserved CVE: CVE-2017-11563

# Description
D-Link EyeOn Baby Monitor (DCS-825L) has a remote code execution vulnerability; a remote attacker can send a crafted request to finder and execute arbitrary code without authentication.

# Vulnerability Type
Buffer Overflow

# Affected Product Code Base
DCS-825L EyeOn Baby Monitor - 1.08.1

# Affected Component
finderd daemon (Device Discovery)

# Attack Type

# Attack Vectors
Send crafted UDP packets to overflow buffer and lead to remote code execution

# Discoverer
Dove Chiu (Trend Micro) and Kenney Lu (Trend Micro)

# Vulnerability Details
A UDP aDiscovera service, which provides multiple functions such as changing the passwords and getting basic information, was installed on the device. An attacker can craft a malicious UDP request to perform stack overflow on the data by using proper ROP (return oriented programming) gadgets to execute an arbitrary code with root privilege on the device.

Reference: https://documents.trendmicro.com/assets/tech_brief_Device_Vulnerabilities_in_the_Connected_Home2.pdf

# Status
Fixed in the latest beta firmware

