Sagem 2604 Router 'password.cgi' Password Disclosure Vulnerability
BID:68027
Info
Sagem 2604 Router 'password.cgi' Password Disclosure Vulnerability
| Bugtraq ID: | 68027 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 06 2014 12:00AM |
| Updated: | Jun 06 2014 12:00AM |
| Credit: | TUNISIAN CYBER |
| Vulnerable: |
SAGECOM Sagem 2604 0 |
| Not Vulnerable: | |
Discussion
Sagem 2604 Router 'password.cgi' Password Disclosure Vulnerability
Sagem 2604 Router is prone to a password-disclosure vulnerability due to a design error.
Attackers can exploit this issue to obtain the root user password. This may lead to other attacks.
Sagem 2604 running firmware version 3.21a4G is vulnerable; other versions may also be affected.
Sagem 2604 Router is prone to a password-disclosure vulnerability due to a design error.
Attackers can exploit this issue to obtain the root user password. This may lead to other attacks.
Sagem 2604 running firmware version 3.21a4G is vulnerable; other versions may also be affected.
Exploit / POC
Sagem 2604 Router 'password.cgi' Password Disclosure Vulnerability
An attacker can use web browser to exploit this issue.
An attacker can use web browser to exploit this issue.