Don't Ruck Us Too Hard - Owning All of Ruckus AP devices | Gal Zror | NULLCON Goa 2020

42:22 · 06 Mar 2020 – 07 Mar 2020 · YouTube

About this talk

This talk showcases vulnerability research conducted on Ruckus Networks' access points and Wi-Fi controllers, revealing three instances of pre-authentication remote code execution. The speaker discusses various exploited vulnerabilities, including information leak, authentication bypass, command injection, path traversal, stack overflow, and arbitrary file read/write, confirming all ten CVEs identified in the research. A total of 33 different access point firmware and Wi-Fi controllers were evaluated, all of which were found to be vulnerable. Additionally, the talk introduces the framework utilized in this research, featuring a Ghidra script and a dockerized QEMU full system emulation for simplified cross-architecture research setup. Gal Zror, a research team leader at HCL AppScan, presents this in-depth exploration, drawing on his extensive experience in vulnerability research focused on embedded systems and protocols.

From event

NULLCON Goa 2020

06 Mar 2020 – 07 Mar 2020

All event videos
Back to Watch