[36957] in bugtraq

home help back first fref pref prev next nref lref last post

More details on BID 11408 (3com 3cradsl72 wireless router)

daemon@ATHENA.MIT.EDU (Ivan Casado)
Fri Oct 15 17:56:26 2004

From: "Ivan Casado" <casadoi@ya.com>
To: <bugtraq@securityfocus.com>
Date: Fri, 15 Oct 2004 19:59:05 +0200
Message-ID: <000e01c4b2e0$af3a2ba0$0f02a8c0@rci3>
MIME-Version: 1.0
Content-Type: text/plain;
	charset="iso-8859-1"
Content-Transfer-Encoding: 8bit

Hi,

I'm writing regarding BID 11408. I have this router at home for my ADSL
connection. The software versions of my router are:

   Runtime Code Version 1.05 (Jan 27 2004 14:58:25) 
   Boot Code Version V1.3d 
   Hardware Version 01A 
   ADSL Modem Code Version 13.9.38 


(taken from http://192.168.2.1/index.stm)

Under this environment I describe the URL http://192.168.2.1/app_sta.stm
described in this BID not only discloses some critical information. After I
accessed this URL I could access the rest of the administrative web
interface of the router and view/change any parameter (WEP keys, IP
addresssing, firewall rules, dhcp server configuration....). After I access
this URL the router considers that I´m authenticated.

The router allows to configure if the router can be administered from the
external interface (internet). As a workarround users should turn off this
option. This restricts the vulnerability to internal only users, then
considering that this is a Wireless router the highest level of protection
should be used in the wireless configuration. I recommend using WPA-PSK and
deactivating the ESSID Broadcast option.

Kind regards,
Ivan Casado Ruiz



home help back first fref pref prev next nref lref last post