Netgear DG834G Zebra Process Default Account Password Vulnerability
BID:10935
Info
Netgear DG834G Zebra Process Default Account Password Vulnerability
| Bugtraq ID: | 10935 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 12 2004 12:00AM |
| Updated: | Aug 12 2004 12:00AM |
| Credit: | <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
NetGear DG834G |
| Not Vulnerable: | |
Discussion
Netgear DG834G Zebra Process Default Account Password Vulnerability
It is reported that Netgear DG834G devices contain a default password for their Zebra process. Zebra is a dynamic routing daemon, and contains a telnet-accessible configuration shell.
It is reported that Zebra listens on both the WAN and the internal network interfaces.
By gaining administrative access to Zebra, an attacker has the ability to modify network routes on the device, possibly redirecting traffic or denying network service to legitimate users. They may also be able to exploit latent vulnerabilities in Zebra itself.
Due to code reuse, it is possible that other devices similar to this one are also affected.
It is reported that Netgear DG834G devices contain a default password for their Zebra process. Zebra is a dynamic routing daemon, and contains a telnet-accessible configuration shell.
It is reported that Zebra listens on both the WAN and the internal network interfaces.
By gaining administrative access to Zebra, an attacker has the ability to modify network routes on the device, possibly redirecting traffic or denying network service to legitimate users. They may also be able to exploit latent vulnerabilities in Zebra itself.
Due to code reuse, it is possible that other devices similar to this one are also affected.
Exploit / POC
Netgear DG834G Zebra Process Default Account Password Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Netgear DG834G Zebra Process Default Account Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Netgear DG834G Zebra Process Default Account Password Vulnerability
References:
References:
- DG834G Product Page (Netgear)
- Homepage (Netgear)
- NETGEAR DG834G SPECIAL FEATURE (
)