Exploitation Summary
EIP tracks 3 public exploits for CVE-2016-0801. PoCs published by AbdSec, abdsec, zsaurus.
AI-analyzed exploit summary This exploit generates a malformed WPS Probe Response packet with an overly long device_name field to trigger a buffer overflow in vulnerable Android devices, leading to a denial-of-service (DoS) condition. The packet is broadcasted on a network interface in monitor mode.
Description
The Broadcom Wi-Fi driver in the kernel in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49G, and 6.x before 2016-02-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted wireless control message packets, aka internal bug 25662029.
Exploits (3)
This exploit generates a malformed WPS Probe Response packet with an overly long device_name field to trigger a buffer overflow in vulnerable Android devices, leading to a denial-of-service (DoS) condition. The packet is broadcasted on a network interface in monitor mode.
This repository contains a functional proof-of-concept exploit for CVE-2016-0801, which targets a buffer overflow vulnerability in the WPS (Wi-Fi Protected Setup) implementation of certain Android devices. The exploit crafts a malformed WPS Probe Response packet with an overly long device_name field to trigger a crash or denial-of-service condition.
This repository contains a functional proof-of-concept exploit for CVE-2016-0801, which targets a buffer overflow vulnerability in the WPS (Wi-Fi Protected Setup) implementation of certain Android devices. The exploit crafts a malformed WPS Probe Response packet with an overly long device_name field, causing a denial-of-service (DoS) condition on vulnerable devices.
References (13)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H