COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
BID:32975
Info
COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
| Bugtraq ID: | 32975 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 22 2008 12:00AM |
| Updated: | Apr 27 2009 07:26PM |
| Credit: | Daniel Fernandez Bleda |
| Vulnerable: |
Comtrend HG-536+ A101-302JAZ-C03_R14. Comtrend HG-536+ A101-302JAZ-C01_R05 Comtrend CT-536 A101-302JAZ-C01_R05 |
| Not Vulnerable: | |
Discussion
COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
COMTREND CT-536 and HG-536 are prone to multiple remote vulnerabilities:
- Multiple unauthorized-access vulnerabilities
- An information-disclosure vulnerability
- Multiple cross-site scripting vulnerabilities
- A denial-of-service vulnerability
- Multiple buffer-overflow vulnerabilities
Attackers can exploit these issues to compromise the affected device, obtain sensitive information, execute arbitrary script code, steal cookie-based authentication credentials, and cause a denial-of-service condition. Other attacks are also possible.
The following firmware versions are vulnerable; additional versions may also be affected:
CT-536 A101-302JAZ-C01_R05
HG-536+ A101-302JAZ-C01_R05 and A101-302JAZ-C03_R14.A2pB021g.d15h
COMTREND CT-536 and HG-536 are prone to multiple remote vulnerabilities:
- Multiple unauthorized-access vulnerabilities
- An information-disclosure vulnerability
- Multiple cross-site scripting vulnerabilities
- A denial-of-service vulnerability
- Multiple buffer-overflow vulnerabilities
Attackers can exploit these issues to compromise the affected device, obtain sensitive information, execute arbitrary script code, steal cookie-based authentication credentials, and cause a denial-of-service condition. Other attacks are also possible.
The following firmware versions are vulnerable; additional versions may also be affected:
CT-536 A101-302JAZ-C01_R05
HG-536+ A101-302JAZ-C01_R05 and A101-302JAZ-C03_R14.A2pB021g.d15h
Exploit / POC
COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
Some of these issues may be exploited through a web browser. Other issues may require attackers to use readily available command-line utilities or network utilities. The cross-site scripting issue will require the attacker to entice unsuspecting victims to follow a malicious URI.
The following example URI is available:
Some of these issues may be exploited through a web browser. Other issues may require attackers to use readily available command-line utilities or network utilities. The cross-site scripting issue will require the attacker to entice unsuspecting victims to follow a malicious URI.
The following example URI is available:
Solution / Fix
COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for these issues. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
COMTREND CT-536 and HG-536 Routers Multiple Remote Vulnerabilities
References:
References:
- Comtrend HG536+ vulnerabilities (Lostmon)
- Vendor Homepage (Comtrend)
- [ISecAuditors Security Advisories] Multiple vulnerabilities in WiFi COMTREND CT (ISecAuditors Security Advisories
)