Telindus 1100 Series Router Administration Password Leak Vulnerability
BID:4946
Info
Telindus 1100 Series Router Administration Password Leak Vulnerability
| Bugtraq ID: | 4946 |
| Class: | Design Error |
| CVE: |
CVE-2002-0949 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 05 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Vulnerability discovery credited to <[email protected]> and <[email protected]>. |
| Vulnerable: |
Telindus 1120 ADSL Router 6.0 .21B Firmware Telindus 1120 ADSL Router Telindus 1110 ADSL Router |
| Not Vulnerable: | |
Discussion
Telindus 1100 Series Router Administration Password Leak Vulnerability
The 1100 series routers are a broadband connectivity solution distributed by Telindus.
Under some circumstances, a vulnerable Telindus router may leak sensitive information. When an attempt to connect to the router is made using the administrative software, the router sends the password to the client in plain text. This packet is sent via UDP.
**The vendor has released firmware version 6.0.27, dated July 2002. Reports suggest that this firmware does not adequately protect against this vulnerability. The firmware is reported to use an encrypted UDP packet when connecting to the router. However, the firmware uses a weak encryption scheme and thus it is easily circumvented by an attacker.
The 1100 series routers are a broadband connectivity solution distributed by Telindus.
Under some circumstances, a vulnerable Telindus router may leak sensitive information. When an attempt to connect to the router is made using the administrative software, the router sends the password to the client in plain text. This packet is sent via UDP.
**The vendor has released firmware version 6.0.27, dated July 2002. Reports suggest that this firmware does not adequately protect against this vulnerability. The firmware is reported to use an encrypted UDP packet when connecting to the router. However, the firmware uses a weak encryption scheme and thus it is easily circumvented by an attacker.
Exploit / POC
Telindus 1100 Series Router Administration Password Leak Vulnerability
No exploit is required for this vulnerability.
An exploit has been made available by <[email protected]>.
A sniffer application called TSniffer has been developed to exploit this issue by Arescom. TSniffer can be obtained from the following location:
http://net.supereva.it/noobsaibot.superdada/tsniffer/tslib.zip_
No exploit is required for this vulnerability.
An exploit has been made available by <[email protected]>.
A sniffer application called TSniffer has been developed to exploit this issue by Arescom. TSniffer can be obtained from the following location:
http://net.supereva.it/noobsaibot.superdada/tsniffer/tslib.zip_
Solution / Fix
Telindus 1100 Series Router Administration Password Leak Vulnerability
Solution:
The vendor has released firmware 6.0.27, dated July 2002. Reports suggest that this firmware revision does not adequately fix the vulnerability.
Users are advised to contact the vendor for firmware updates.
Solution:
The vendor has released firmware 6.0.27, dated July 2002. Reports suggest that this firmware revision does not adequately fix the vulnerability.
Users are advised to contact the vendor for firmware updates.
References
Telindus 1100 Series Router Administration Password Leak Vulnerability
References:
References: