Longshine Wireless Access Point Devices Information Disclosure Vulnerability
BID:6533
Info
Longshine Wireless Access Point Devices Information Disclosure Vulnerability
| Bugtraq ID: | 6533 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 06 2003 12:00AM |
| Updated: | Jan 06 2003 12:00AM |
| Credit: | Discovery of this vulnerability credited to Lukas Grunwald <[email protected]>. |
| Vulnerable: |
Longshine Technologies LCS-883R-AC-B D-Link DI-614+ 2.0 |
| Not Vulnerable: | |
Discussion
Longshine Wireless Access Point Devices Information Disclosure Vulnerability
The Longshine LCS-883R-AC-B device will allow tftp connections. An attacker can exploit this vulnerability to connect via tftp to the access point and download the configuration file without any authentication.
The configuration file contains sensitive information including the administrator password and WEP keys.
** The D-Link DI-614+ product, reportedly based on the Longshine device, appears to be vulnerable to this issue however, only some files were accessible.
The Longshine LCS-883R-AC-B device will allow tftp connections. An attacker can exploit this vulnerability to connect via tftp to the access point and download the configuration file without any authentication.
The configuration file contains sensitive information including the administrator password and WEP keys.
** The D-Link DI-614+ product, reportedly based on the Longshine device, appears to be vulnerable to this issue however, only some files were accessible.
Exploit / POC
Longshine Wireless Access Point Devices Information Disclosure Vulnerability
There is no exploit code required.
There is no exploit code required.
Solution / Fix
Longshine Wireless Access Point Devices Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Longshine Wireless Access Point Devices Information Disclosure Vulnerability
References:
References:
- Longshines Wireless Ethernet Access Point (Longshine Technologies)
- Longshine WLAN Access-Point LCS-883R VU#310201 (Lukas Grunwald
) - Re: Longshine WLAN Access-Point LCS-883R VU#310201 ([email protected])