ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
BID:14364
Info
ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
| Bugtraq ID: | 14364 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 25 2005 12:00AM |
| Updated: | Jul 25 2005 12:00AM |
| Credit: | Discovery is credited to D . <[email protected]>. |
| Vulnerable: |
ECI Telecom B-FOCuS Router 312+ |
| Not Vulnerable: | |
Discussion
ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
B-FOCuS Router 312+ is affected by a vulnerability that can allow unauthorized attackers to gain access to an affected device.
An attacker can disclose the administrator password through the Web interface of the device.
This can lead to a complete compromise of the router.
B-FOCuS Router 312+ is affected by a vulnerability that can allow unauthorized attackers to gain access to an affected device.
An attacker can disclose the administrator password through the Web interface of the device.
This can lead to a complete compromise of the router.
Exploit / POC
ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/cgi-bin/firmwarecfg
An exploit is not required.
The following proof of concept example is available:
http://www.example.com/cgi-bin/firmwarecfg
Solution / Fix
ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
ECI Telecom B-FOCuS Router 312+ Unauthorized Access Vulnerability
References:
References:
- B-FOCuS? xDSL Modem Family (ECI Telecom)
- ECI router login bypass ("D ."
)