SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
BID:50489
Info
SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
| Bugtraq ID: | 50489 |
| Class: | Design Error |
| CVE: |
CVE-2011-3682 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 01 2011 12:00AM |
| Updated: | Nov 01 2011 12:00AM |
| Credit: | TAN SZE CHUEN |
| Vulnerable: |
Singtel 2Wire firmware 5 |
| Not Vulnerable: |
Singtel 2Wire firmware 6 |
Discussion
SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
SingTel 2Wire is prone to a vulnerability that allows attackers to bypass certain security restrictions.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions, such as altering the router's settings.
SingTel 2Wire firmware versions 5 and below are affected.
SingTel 2Wire is prone to a vulnerability that allows attackers to bypass certain security restrictions.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions, such as altering the router's settings.
SingTel 2Wire firmware versions 5 and below are affected.
Exploit / POC
SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
Solution:
Reportedly the issue is patched in firmware version 6. Please contact the vendor for more information.
Solution:
Reportedly the issue is patched in firmware version 6. Please contact the vendor for more information.
References
SingTel 2Wire Hardcoded Password Security Bypass Vulnerability
References:
References:
- CVE-2011-3682: 2WIRE-SINGTEL 2701HGV-E/2700HGV-2/2700HG GATEWAY ROUTER MANAGEMEN (TAN SZE CHUEN)
- SingTel Homepage (SingTel)