SpeedXess HA-120 Router Default Administrative Password Vulnerability
BID:3617
Info
SpeedXess HA-120 Router Default Administrative Password Vulnerability
| Bugtraq ID: | 3617 |
| Class: | Configuration Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Dec 04 2001 12:00AM |
| Updated: | Dec 04 2001 12:00AM |
| Credit: | This vulnerability was announced in a WOWHACKER Security Advisory on December 04, 2001. |
| Vulnerable: |
Hyundai HA-120 HASE-120-1101 |
| Not Vulnerable: | |
Discussion
SpeedXess HA-120 Router Default Administrative Password Vulnerability
The SpeedXess HA-120 router is a home-grade hardware solution used to route DSL connections. It is manufactured by Hyundai Networks.
When installed, the router does not prompt the user to change the password. Added to this problem is the fact that the factory sets the password to a known default for every router.
Therefore, it is possible for a remote user to gain unauthorized administrative access to all HA-120 routers that have been installed without the changing of the default password.
The SpeedXess HA-120 router is a home-grade hardware solution used to route DSL connections. It is manufactured by Hyundai Networks.
When installed, the router does not prompt the user to change the password. Added to this problem is the fact that the factory sets the password to a known default for every router.
Therefore, it is possible for a remote user to gain unauthorized administrative access to all HA-120 routers that have been installed without the changing of the default password.
Exploit / POC
SpeedXess HA-120 Router Default Administrative Password Vulnerability
No exploit is required for this vulnerability.
No exploit is required for this vulnerability.
References
SpeedXess HA-120 Router Default Administrative Password Vulnerability
References:
References: