Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
BID:32271
Info
Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
| Bugtraq ID: | 32271 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 12 2008 12:00AM |
| Updated: | Nov 14 2008 05:14PM |
| Credit: | Craig Heffner and Derek Yap of SourceSec |
| Vulnerable: |
Actiontec MI424WR 0 |
| Not Vulnerable: | |
Discussion
Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
ActionTec MI424WR is prone to a security-bypass vulnerability because it uses a default WEP encryption key.
Successful exploits will allow attackers to trivially decrypt wireless network traffic. Information obtained may aid in further attacks.
ActionTec MI424WR is prone to a security-bypass vulnerability because it uses a default WEP encryption key.
Successful exploits will allow attackers to trivially decrypt wireless network traffic. Information obtained may aid in further attacks.
Exploit / POC
Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Actiontec MI424WR Default WEP Key Security Bypass Vulnerability
References:
References:
- Hacking SOHO Routers (SourceSec)
- MI424WR Wireless Broadband Router Homepage (Actiontec)