[NEWS] Configuration Disclosure on Sweex 802.11g Wireless Accesspoint/Router

From: SecuriTeam (support_at_securiteam.com)
Date: 05/20/04

  • Next message: SecuriTeam: "[UNIX] OpenBSD Procfs Memory Disclosure Vulnerability"
    To: list@securiteam.com
    Date: 20 May 2004 17:49:41 +0200
    
    

    The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
    - - promotion

    The SecuriTeam alerts list - Free, Accurate, Independent.

    Get your security news from a reliable source.
    http://www.securiteam.com/mailinglist.html

    - - - - - - - - -

      Configuration Disclosure on Sweex 802.11g Wireless Accesspoint/Router
    ------------------------------------------------------------------------

    SUMMARY

    Any client connected to the access point can discover critical elements of
    the Sweex 802.11g access point's configuration. This includes the
    administration username and password.

    DETAILS

    Vulnerable Systems:
     * Sweex Wireless Broadband Router/Access point 802.11g (LC000060)
     * Unex WF514 (Unverified, but this appears to be the same device)

    The configuration of the access point can be 'backed-up' using TFTP from
    any client that is connected to the access point by requesting any
    filename from the TFTP server (default 192.168.61.1) as long as the name
    starts with 'nvram'.

    Running strings(1) on the nvram file then reveals the admin username and
    password and other configuration data. Using the username and password the
    configuration web interface can be accessed to modify the entire
    configuration.

    If the access point is also used as a Broadband router that the username
    and passwords of these connections is also revealed.

    ADDITIONAL INFORMATION

    The information has been provided by <mailto:maniac@maniac.nl> Mark
    Janssen.

    ========================================

    This bulletin is sent to members of the SecuriTeam mailing list.
    To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@securiteam.com
    In order to subscribe to the mailing list, simply forward this email to: list-subscribe@securiteam.com

    ====================
    ====================

    DISCLAIMER:
    The information in this bulletin is provided "AS IS" without warranty of any kind.
    In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.


  • Next message: SecuriTeam: "[UNIX] OpenBSD Procfs Memory Disclosure Vulnerability"

    Relevant Pages

    • [NT] Anon Proxy Server Buffer Overflow
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Anon Proxy Server Buffer Overflow ... passing a long username containing quotes. ...
      (Securiteam)
    • [NT] SecureCRT Remote Command Execution
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Unsafe handling of a URL handler in SecureCRT ... allowing them to control the configuration of SecureCRT. ... SecureCRT allows for 'scripting' using script languages such as VBScript ...
      (Securiteam)
    • [NEWS] UTStarcoms iAN-02EX Remote Access Vulnerability
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... next-generation, standards-based Voice-over-IP (VoIP) communications ... configuration leaves the ATA vulnerable to unauthorized remote access. ... This configuration makes the ATA's WAN port ...
      (Securiteam)
    • [NT] Compaq Web Management Vulnerability (Secure Task Execution)
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... it, a common configuration, then a bug in the validation system allows ... * All known Compaq Web Management are effected. ... * HP Version Control Repository Agent ...
      (Securiteam)
    • [TOOL] URCS - Unmanarc Remote Control Server
      ... The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com ... Reverse proxy system ... Configuration over URL (Any configuration parameter can be obtained from ... Process manipulation commands ...
      (Securiteam)