The GL-iNet Mango Travel Router & CVE-2022-31898

I had an hour or two to kill before a dentist appointment last summer, so I pulled out the GL-iNet Mango v2 Travel Router I had bought to hack on in just this type of situation. At 30$ and about the size of a credit card, I figured I was bound to find something. And boy, did it not take long. After opening up the firmware in Ghidra and searching for calls to system() as a first shot, I…

Continue reading