Re: Router ZyXEL Prestige 650 HW http remote admin.

From: Steve Clement (steve_at_ion.lu)
Date: 11/24/04

  • Next message: advisory_at_stgsecurity.com: "STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability"
    Date: Wed, 24 Nov 2004 01:10:30 +0100
    To: QFrancisco_=5C=22Jos=E9=5C=22_Canela=22?= <darkydelphi@gmail.com>
    
    

    Francisco Josť Canela wrote:

    >Hi, I found a bug in ZyXEL Prestige 650 HW Routers with Http Remote Administration active.
    >
    >
    >
    Prestige 623/652 are also vulnerable which is very sad, have you
    contacted Zyxel about it? If so, how patient have you been?
    This is really annoying because it is really easy to "exploit" and
    without a working firmware I will have to disable the Web Management on
    all my remote clients because it is "usuallly" on by default.

    jeers,

    Steve C

    >Exploting this bug, the attacker can reset the router configurantion.
    >
    >The "/rpFWUpload.html" is not password protected. To exploit this bug you only need write that:
    >
    >http://[Router ip]/rpFWUpload.html
    >
    >and click the Reset button.
    >
    >
    >Sorry if this post is misspelling... but I'm from Spain and my english level is poor...
    >
    >


  • Next message: advisory_at_stgsecurity.com: "STG Security Advisory: [SSA-20041122-10] KorWeblog directory traversal vulnerability"

    Relevant Pages

    • Re: Obama nine months in...
      ... patient. ... Really sad attempt at deflecting attention to other people to take heat off ... I actually work with mental patients everyday there Bubba and have ... you and your trollboy pals who remain willfully, even proudly ignorant ...
      (rec.music.artists.springsteen)
    • Re: aes decrypt encrypt
      ... talks, sugars, and greeks are all patient and sad. ... We reverse the ... mature sheet. ...
      (sci.crypt)
    • Re: about rules of conduct / hygiene in dental office
      ... There is nothing patient can do to be sure all the tools are sterilized properly... ... So sad! ...
      (sci.med.dentistry)