ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
BID:20834
Info
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
| Bugtraq ID: | 20834 |
| Class: | Design Error |
| CVE: |
CVE-2006-5711 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 31 2006 12:00AM |
| Updated: | Jul 06 2007 08:07PM |
| Credit: | LegendaryZion is credited with the discovery of this vulnerability. |
| Vulnerable: |
ECI Telecom B-FOCuS ADSL2+ Combo 332+ Wireless Router 0 |
| Not Vulnerable: | |
Discussion
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
ECI Telecom's B-FOCuS ADSL2+ Combo332+ wireless router is prone to an information-disclosure vulnerability. The router's Web-Based Management interface fails to authenticate users before providing access to sensitive information.
Exploiting this issue may allow an unauthenticated remote attacker to retrieve sensitive information from the affected device, which may aid in further attacks.
ECI Telecom's B-FOCuS ADSL2+ Combo332+ wireless router is prone to an information-disclosure vulnerability. The router's Web-Based Management interface fails to authenticate users before providing access to sensitive information.
Exploiting this issue may allow an unauthenticated remote attacker to retrieve sensitive information from the affected device, which may aid in further attacks.
Exploit / POC
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/html/defs/
Attackers can use a browser to exploit this issue.
The following proof-of-concept URI is available:
http://www.example.com/html/defs/
Solution / Fix
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: mailto:[email protected].
References
ECI Telecom B-Focus ADSL2+ Combo332+ Wireless Router Information Disclosure Vulnerability
References:
References:
- Product Homepage (ECI Telecom)
- Directory listing on B-FOCuS Wireless 802.11b/g ADSL2+ Router by "ECI Telecom LT (LegendaryZion)