CVE-2014-1201
Lorex Edge Series - Buffer Overflow via HTTP_PORT Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-1201. PoCs published by Pedro Ribeiro.
AI-analyzed exploit summary This is a working proof-of-concept for a buffer overflow vulnerability in the Lorex Technologies INetViewX ActiveX control, allowing remote code execution via a long string in the HTTP_PORT parameter.
Description
Buffer overflow in the INetViewX ActiveX control in the Lorex Edge LH310 and Edge+ LH320 series with firmware 7-35-28-1B26E, Edge2 LH330 series with firmware 11.17.38-33_1D97A, and Edge3 LH340 series with firmware 11.19.85_1FE3A allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the HTTP_PORT parameter.
Exploits (1)
This is a working proof-of-concept for a buffer overflow vulnerability in the Lorex Technologies INetViewX ActiveX control, allowing remote code execution via a long string in the HTTP_PORT parameter.