Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
BID:11102
Info
Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
| Bugtraq ID: | 11102 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 03 2004 12:00AM |
| Updated: | Sep 03 2004 12:00AM |
| Credit: | fabio <[email protected]> disclosed this vulnerability. |
| Vulnerable: |
Dynalink RTA 230 ADSL Router |
| Not Vulnerable: | |
Discussion
Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
The Dynalink RTA 230 ADSL router is reported susceptible to a default backdoor account vulnerability.
It is reported that the firmware contains a backdoor account. This account is not visible or modifiable from the web administration interface. Both the web configuration application and the telnet service are not listening on the WAN interface by default.
Attackers with network access to internal interfaces of the device can gain complete access to a vulnerable access point by using the default credentials.
Other devices utilizing similar firmware may also be affected, but this has not been confirmed. Other potential devices reported are:
- US Robotics 9105 and 9106
- Siemens SE515
- Buffalo WMR-G54
The Dynalink RTA 230 ADSL router is reported susceptible to a default backdoor account vulnerability.
It is reported that the firmware contains a backdoor account. This account is not visible or modifiable from the web administration interface. Both the web configuration application and the telnet service are not listening on the WAN interface by default.
Attackers with network access to internal interfaces of the device can gain complete access to a vulnerable access point by using the default credentials.
Other devices utilizing similar firmware may also be affected, but this has not been confirmed. Other potential devices reported are:
- US Robotics 9105 and 9106
- Siemens SE515
- Buffalo WMR-G54
Exploit / POC
Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
An exploit is not required.
An exploit is not required.
Solution / Fix
Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Dynalink RTA 230 ADSL Router Default Backdoor Account Vulnerability
References:
References:
- RTA 230 Product Page (Dynalink)
- Dynalink routers backdoor? (fabio
)