ZeroHour
ZDI Published Advisoriespublished ()ingested

ZDI-26-559: (Pwn2Own) Amazon Smart Plug OTA Update Process Out-Of-Bounds Write Remote Code Execution Vulnerability

mediumAdvisoryimportance 30
AI summary · glm-5.3-flash

ZDI disclosed a Pwn2Own out-of-bounds write RCE (CVSS 7.5) in Amazon Smart Plug's OTA process, exploitable by unauthenticated network-adjacent attackers.

The Zero Day Initiative published ZDI-26-559 for an out-of-bounds write remote code execution flaw in the Amazon Smart Plug OTA update process, demonstrated at Pwn2Own. Unauthenticated network-adjacent attackers can execute arbitrary code on affected installations. ZDI rated the issue CVSS 7.5.

  • Out-of-bounds write in the OTA process allows unauthenticated network-adjacent code execution.
  • ZDI assigned CVSS 7.5; bug demonstrated at Pwn2Own.
Full article

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Amazon Smart Plug. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5.

This source does not provide full text. Read it at zerodayinitiative.com.