Alcatel Speed Touch Pro ADSL Insecure Embedded TFTP Server Vulnerability

BID:2566

Info

Alcatel Speed Touch Pro ADSL Insecure Embedded TFTP Server Vulnerability

Bugtraq ID: 2566
Class: Design Error
CVE:
Remote: Yes
Local: No
Published: Apr 10 2001 12:00AM
Updated: Apr 10 2001 12:00AM
Credit: Discovered by Tsutomu Shimomura. Reported to bugtraq by Tom Perrine <[email protected]> on 10 Apr 2001
Vulnerable: Alcatel Speed Touch Home KHDSAA.134
Alcatel Speed Touch Home KHDSAA.133
Alcatel Speed Touch Home KHDSAA.132
Alcatel Speed Touch Home KHDSAA.108
Not Vulnerable:

Discussion

Alcatel Speed Touch Pro ADSL Insecure Embedded TFTP Server Vulnerability

The Alcatel Speed Touch family of ADSL-Ethernet router/bridge products exhibit several serious security flaws.

Certain Alcatel ADSL-Ethernet bridge products feature an embedded TFTP server which can be used by remote users to make changes to configuration and firmware.

Normally, the TFTP service in such a device would not be accessible from the WAN.

In this case, however, the interface is available to both extranet users and attackers local to the copper loop on which the DSL connection is carried.

Since TFTP provides no support for user authentication, this leaves the device's admin interface and firmware upload feature completely open to any attacker.

Moreover, user-supplied firmware code transferred to the router/bridge is not checked for authenticity, and an attacker may exploit the open TFTP interface to install malicious code on the device.

No method is available for disabling the vulnerable TFTP service.

*** NOTE: Shortly after this advisory was published, the vendor, Alcatel, posted their response to the reported vulnerabilities in their modems.

In addition to providing general mitigating strategies designed to lessen the impact of these isses (such as firewall software and/or a dedicated firewall device or the Alcatel Speed Touch modem with Firewall capabilities), the vendor response indicates that only the Speed Touch Pro is vulnerable to remote changes to firmware code and configuration settings, and that this model can be made secure from such interference by the activation of an inbuilt security feature disabling remote access from the WAN/DSL interface. Therefore, while the discoverer's initial advisory states that the entire family of devices may be vulnerable, the vendor limits the scope of this vulnerability to a single, misconfigured model of the Speed Touch line.

This discussion will be updated regularly as further details and clarification emerge.

Solution / Fix

Alcatel Speed Touch Pro ADSL Insecure Embedded TFTP Server Vulnerability

Solution:
Configuring the security of your Alcatel Speed Touch Pro modem:

Setup a telnet connection to your modem.
Telnet address is 10.0.0.138
Consult your Operation System manual on how to setup a telnet connection.

Type "Enter" at the User Name prompt

Wait for the next prompt and then type the following:
=> ip config

The information on you firmware protection feature is given in the second line of the response

If it is "ON", your modem has the security features activated and you have nothing to worry about.

If it is "OFF", you are vulnerable to the attacks.

You can adjust the security settings as follows:
=> ip config firewalling on
=> config save
Now you are safe again!

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report