2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
BID:36075
Info
2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
| Bugtraq ID: | 36075 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 18 2009 12:00AM |
| Updated: | Aug 21 2009 03:56PM |
| Credit: | bugz |
| Vulnerable: |
2Wire OfficePortal 0 2Wire HomePortal 1500W 2Wire HomePortal 100W 2Wire HomePortal 100S 2Wire HomePortal 1000W 2Wire HomePortal 1000SW 2Wire HomePortal 1000S 2Wire HomePortal 1000 2Wire HomePortal 0 2Wire 3800 HGV-B 5.29.105 2Wire 3800 HGV-B 5.29.33 2Wire 2700HG Gateway 5.29.51 2Wire 2700HG Gateway 4.25.19 2Wire 2700HG Gateway 3.17.5 2Wire 2700HG Gateway 3.7.1 2Wire 2071HG 5.29.51 2Wire 2071HG 4.25.19 2Wire 2071HG 3.17.5 2Wire 2071HG 3.7.1 2Wire 2071 Gateway 5.29.135 .5 2Wire 2071 Gateway 5.29.51 2Wire 2071 Gateway 3.17.5 2Wire 2071 Gateway 3.7.1 2Wire 1800HW 5.29.135 .5 2Wire 1800HW 5.29.51 2Wire 1800HW 4.25.19 2Wire 1800HW 3.17.5 2Wire 1800HW 3.7.1 2Wire 1701HG 5.29.135 .5 2Wire 1701HG 5.29.51 2Wire 1701HG 4.25.19 2Wire 1701HG 3.17.5 2Wire 1701HG 3.7.1 |
| Not Vulnerable: | |
Discussion
2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
Multiple 2Wire routers are prone to a security-bypass vulnerability because they fail to adequately authenticate users before performing certain actions.
Unauthenticated attackers can leverage this issue to change the router's administrative password. Successful attacks will completely compromise affected devices.
This issue may be related to the vulnerability described in BID 36031 (2Wire Routers 'CD35_SETUP_01' Access Validation Vulnerability).
We don't know which models and firmware versions are affected. We will update this BID when more details become available.
Multiple 2Wire routers are prone to a security-bypass vulnerability because they fail to adequately authenticate users before performing certain actions.
Unauthenticated attackers can leverage this issue to change the router's administrative password. Successful attacks will completely compromise affected devices.
This issue may be related to the vulnerability described in BID 36031 (2Wire Routers 'CD35_SETUP_01' Access Validation Vulnerability).
We don't know which models and firmware versions are affected. We will update this BID when more details become available.
Exploit / POC
2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
Attackers can exploit this issue via a browser.
Attackers can exploit this issue via a browser.
Solution / Fix
2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
2Wire Routers 'password_required.html' Password Reset Security Bypass Vulnerability
References:
References:
- 2wire Homepage (2wire)