D-Link DSL-500 Default Telnet Password Vulnerability
BID:6039
Info
D-Link DSL-500 Default Telnet Password Vulnerability
| Bugtraq ID: | 6039 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 24 2002 12:00AM |
| Updated: | Oct 24 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Linux <[email protected]>. |
| Vulnerable: |
D-Link DSL-500 1.14 |
| Not Vulnerable: | |
Discussion
D-Link DSL-500 Default Telnet Password Vulnerability
The DSL-500 is a broadband router appliance distributed by D-Link.
The DSL-500 does not allow the changing of the default telnet password. In the event that an arbitrary user gains access to the telnet password and interface, it would be impossible to restrict unauthorized access by changing the password. This could result in unauthorized access, denial of service, or other problems.
The DSL-500 is a broadband router appliance distributed by D-Link.
The DSL-500 does not allow the changing of the default telnet password. In the event that an arbitrary user gains access to the telnet password and interface, it would be impossible to restrict unauthorized access by changing the password. This could result in unauthorized access, denial of service, or other problems.
Exploit / POC
D-Link DSL-500 Default Telnet Password Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
D-Link DSL-500 Default Telnet Password Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
D-Link DSL-500 Default Telnet Password Vulnerability
References:
References:
- DSL-500 Product Page (in Italian) (D-Link)