Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

BID:10512

Info

Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

Bugtraq ID: 10512
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Jun 10 2004 12:00AM
Updated: Mar 03 2008 11:42PM
Credit: This vulnerability was originally disclosed to Bugtraq by Menno Slaats <[email protected]>.
Vulnerable: Edimax 7205APL 2.40 a-00
Not Vulnerable: Edimax 7205APL 2.70a-00

Discussion

Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

The Edimax 7205APL is reported to contain a default backdoor account.

This account is hard-coded and cannot be removed. This account can be used to log in to the device and to create a backup of the configuration.

This configuration contains all users and their corresponding passwords, allowing an attacker to then log in to the device as administrator.

The reported vulnerable device had firmware revision 2.40a-00. Other revisions may also contain similar backdoor accounts.

Exploit / POC

Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

No exploit is required.

Solution / Fix

Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

Solution:
The vendor released updates to address this issue. Please see the references for more information.


Edimax 7205APL 2.40 a-00

References

Edimax 7205APL 802.11b Wireless Access Point Default Backdoor Account Vulnerability

References:

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report