Experts from Elttam discovered a flaw in GoAhead tiny web server that affects hundreds of thousands of IoT devices. It could be exploited to remotely execute malicious code on affected devices. The solution is widely adopted by tech giants, including Comcast, IBM, Boeing, Oracle, D-Link, ZTE, HP, Siemens, and Canon. Attackers can exploit the vulnerability if the CGI support is enabled with dynamically linked CGI program. Such kind of flaws are exploited by IoT malware like BrickerBot, Mirai, Hajime, and Persirai.”]
Source: http://securityaffairs.co/wordpress/67113/iot/goahead-flaws.html

