Belkin F5D5230-4 Router Internal Web Traffic Origin Obfuscation Vulnerability
BID:4982
Info
Belkin F5D5230-4 Router Internal Web Traffic Origin Obfuscation Vulnerability
| Bugtraq ID: | 4982 |
| Class: | Design Error |
| CVE: |
CVE-2002-1431 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2002 12:00AM |
| Updated: | Jul 11 2009 01:56PM |
| Credit: | Reported by M Freitas <[email protected]>. |
| Vulnerable: |
Belkin F5D5230-4 |
| Not Vulnerable: | |
Discussion
Belkin F5D5230-4 Router Internal Web Traffic Origin Obfuscation Vulnerability
The Belkin F5D5230-4 4-Port Cable/DSL Gateway Router is a hardware router for a home or small office.
When a request for a service that has been remapped to the internal network is made via the WAN interface, and the origin is the internal network, the router reacts unpredictably. The origin address is rewritten as the IP address of the external interface by the device before being passed to the internal network. Upon receiving a request of this nature, the device will rewrite all future requests for services mapped to the WAN network, reporting their origin as that of the WAN interface.
This is known to be an issue for requests for port 80, if port 80 has been remapped to a host within the internal network. This may potentially be exploited to obscure the origin of attacks against a webserver in the internal network.
The Belkin F5D5230-4 4-Port Cable/DSL Gateway Router is a hardware router for a home or small office.
When a request for a service that has been remapped to the internal network is made via the WAN interface, and the origin is the internal network, the router reacts unpredictably. The origin address is rewritten as the IP address of the external interface by the device before being passed to the internal network. Upon receiving a request of this nature, the device will rewrite all future requests for services mapped to the WAN network, reporting their origin as that of the WAN interface.
This is known to be an issue for requests for port 80, if port 80 has been remapped to a host within the internal network. This may potentially be exploited to obscure the origin of attacks against a webserver in the internal network.
Solution / Fix
Belkin F5D5230-4 Router Internal Web Traffic Origin Obfuscation Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Belkin F5D5230-4 Router Internal Web Traffic Origin Obfuscation Vulnerability
References:
References:
- F5D5230-4 Product Homepage (Belkin)