FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
BID:20154
Info
FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
| Bugtraq ID: | 20154 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 22 2006 12:00AM |
| Updated: | Sep 22 2006 11:06PM |
| Credit: | Zachary McGrew is credited with the discovery of this vulnerability. |
| Vulnerable: |
FiWin SS28S WiFi VoIP SIP/Skype Phone firmware 01_02_07 |
| Not Vulnerable: | |
Discussion
FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
The FiWin SS28S WiFi VoIP SIP/Skype phone is prone to an authentication-bypass vulnerability because the administrator password is hard-coded into the device.
An attacker can exploit this issue to bypass authentication and gain access to the device's administrative section. This could aid in further attacks.
The FiWin SS28S WiFi VoIP SIP/Skype phone is prone to an authentication-bypass vulnerability because the administrator password is hard-coded into the device.
An attacker can exploit this issue to bypass authentication and gain access to the device's administrative section. This could aid in further attacks.
Exploit / POC
FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
Attackers can exploit this issue through a telnet client.
Attackers can exploit this issue through a telnet client.
Solution / Fix
FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
References
FiWin SS28S WiFi VoIP SIP/Skype Phone Default Administrator Password Vulnerability
References:
References: