[VulnWatch] Efficient Networks 5861 DSL Router

From: Greg Bolshaw (greg@optionsinternet.com)
Date: 01/10/03

  • Next message: Ofir Arkin: "[VulnWatch] More information regarding Etherleak"
    From: "Greg Bolshaw" <greg@optionsinternet.com>
    To: <vulnwatch@vulnwatch.org>, <bugtraq@securityfocus.com>
    Date: Fri, 10 Jan 2003 11:05:01 -0000
    
    

    Product: Efficient Networks 5861 DSL Router
                            http://www.efficient.com/ebz/5800.html
    Tested version: 5.3.80 (Latest firmware)
    Advisory date: 10/01/2003
    Severity: Moderate

    Background

    "Efficient Networks® Business Class IDSL, ADSL, or SDSL Routers provide DSL
    access for up to 100 or more users with robust firewall and optional Secure
    Virtual Private Network (VPN) capabilities. Efficient Networks® Business
    Class DSL Routers are Business Contingency Plan ready, with features such as
    Dial Backup and Virtual Router Redundancy Protocol (VRRP)."

    As far as I am aware, the 5861 is the standard router provided to all ADSL
    business customers in the UK.

    Details

    When using the builtin IP filtering to block incoming TCP SYN flags, a
    simple portscan to the WAN interface of the router will cause the it to lock
    up, and eventually restart.

    This has been tested on two different 5861 routers, both running the above
    firmware version.

    Port scanners used were Nmap (Linux) and SuperScan (Windows)

    Solution

    There is currently no fix for this exploit. I have contacted Efficient
    Networks to inform them of the problem.



    Relevant Pages

    • Re: The OTHER problem with Netgear WGT624 (and probably others)
      ... |>You have not yet justified why _routers_ should enjoy the extra $250 ... | large medical office systems as customers. ... | The issue was over what downtime will cost the company. ... small business needs to consider routers to be worth the expense when ...
      (alt.internet.wireless)
    • Efficient Networks 5861 DSL Router
      ... "Efficient Networks® Business Class IDSL, ADSL, or SDSL Routers provide DSL ...
      (Bugtraq)
    • Re: 10mbit fiber to home; NAT router cant fill pipe
      ... "Not exactly industrial strength, but take a look at the D-link ... routers,.I have the 4100. ... and has a 10/100 Mb WAN side connection and 10/100/1000 LAN ... My problem with retail/consumer products for business use is any ...
      (comp.dcom.lans.ethernet)
    • Re: Advice on always on connections
      ... the computer and the ADSL modem on all the time. ... delay the first time an ADSL modem establishes connection. ... is based on the use of a USB modem or perhaps a PCI modem. ... Various routers can be had for under 40 quid, ...
      (uk.telecom.broadband)
    • Re: ADSL interface attenuation
      ... Zyxel routers can do time-based access rules. ... Getting a DSL ... until the firmware was changed. ... the IOS and is a free download. ...
      (comp.dcom.sys.cisco)