2Wire Routers 'H04_POST' Access Validation Vulnerability
BID:27516
Info
2Wire Routers 'H04_POST' Access Validation Vulnerability
| Bugtraq ID: | 27516 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 30 2008 12:00AM |
| Updated: | Feb 05 2008 02:36AM |
| Credit: | Oligarchy Oligarchy <[email protected]> and Eduardo Espina García both claim credit for the discovery of this vulnerability. |
| Vulnerable: |
2Wire 3800 HGV-B 5.29.105 2Wire 3800 HGV-B 5.29.33 2Wire 2071 Gateway 5.29.51 2Wire 2071 Gateway 3.17.5 2Wire 2071 Gateway 3.7.1 2Wire 1800HW 5.29.51 2Wire 1800HW 3.17.5 2Wire 1800HW 3.7.1 2Wire 1701HG 5.29.51 2Wire 1701HG 3.17.5 2Wire 1701HG 3.7.1 |
| Not Vulnerable: | |
Discussion
2Wire Routers 'H04_POST' Access Validation Vulnerability
Multiple 2Wire routers are prone to an access-validation vulnerability because they fail to adequately authenticate users before performing certain actions.
Unauthenticated attackers can leverage this issue to change the password of arbitrary user accounts on the router. Successful attacks will completely compromise affected devices.
2Wire routers that have the 'H04_POST' page are affected by this issue.
UPDATE: This BID has been retired because it has been found to be a duplicate of BID 27246 (2Wire Routers Cross-Site Request Forgery Vulnerability).
UPDATE (February 1, 2008): This BID is being reinstated. Further investigation and new information reveal that this vulnerability differs from the one described in BID 27246.
Multiple 2Wire routers are prone to an access-validation vulnerability because they fail to adequately authenticate users before performing certain actions.
Unauthenticated attackers can leverage this issue to change the password of arbitrary user accounts on the router. Successful attacks will completely compromise affected devices.
2Wire routers that have the 'H04_POST' page are affected by this issue.
UPDATE: This BID has been retired because it has been found to be a duplicate of BID 27246 (2Wire Routers Cross-Site Request Forgery Vulnerability).
UPDATE (February 1, 2008): This BID is being reinstated. Further investigation and new information reveal that this vulnerability differs from the one described in BID 27246.
Exploit / POC
2Wire Routers 'H04_POST' Access Validation Vulnerability
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/xslt?PAGE=H04_POST&PASSWORD=admin&PASSWORD_CONF=admin
Attackers can exploit this issue via a browser.
The following example URI is available:
http://www.example.com/xslt?PAGE=H04_POST&PASSWORD=admin&PASSWORD_CONF=admin
Solution / Fix
2Wire Routers 'H04_POST' Access Validation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].