Executive brief
A security vulnerability exists in the Sagemcom F@st 3686 router, a device used to provide internet connectivity. The flaw is found in the router's network printing service, which is enabled by default. An attacker can exploit this to take complete control of the device, potentially allowing them to intercept network traffic or disrupt internet service.
Technical details
A classic buffer overflow (CWE-120) exists in the 'ippprint' (Internet Printing Protocol) service of the Sagemcom F@st 3686 router. The vulnerability is located in the 'httpGetExpect' function (offset 0x00404924), where an 'sscanf' call reads the 'Expect' HTTP header into a fixed 16-byte array without bounds checking. An attacker can provide a long string in this header to overwrite the $RA register. Exploitation is facilitated by the lack of modern binary protections such as PIE, NX, or stack canaries, though the service does not automatically restart upon crashing, which may complicate repeated exploitation attempts.
Affected products
- Sagemcom F@st 3686 firmware MAGYAR_4.121.0
Timeline
- 2025-01-12: disclosed
- 2026-01-12: advisory: NVD publication date