Informational December 18, 2014
Command Execution and Backdoor in Zhone GPON-2520
This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.
Informational May 22, 2014
Huawei HG8245 / HG8247 WPA Generator
Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).
Informational December 19, 2013
Arbitrary Command Execution in Alcatel-Lucent I-240W-Q
The ONT Alcatel-Lucent I-240W-Q is vulnerable to arbitrary command execution in the administrative web interface.
Informational December 9, 2013
Huawei HG8245 backdoor and remote access
The Huawei HG8245 ONT, firmware version V1R006C00S100 which provides cellular services, contains 3 severe vulnerabilities: two administrator accounts enabled by default and a public administration interface exposed to the Internet.
Informational January 18, 2013
Multiple vulnerabilities in ZPanel 10.0.1
Several vulnerabilties were discovered in ZPanel 10.0.1 during our pro bono security audit. The ZPanel team has addressed these issues in version 10.0.2 and it is advised to upgrade.
Informational June 18, 2012
Debugging shell with root privileges in routers TP-Link WR740
There is a hidden debugging shell with root privileges in routers TP-Link WR740.
Informational June 17, 2012
Path traversal in TP-LINK WR740 and possibly others
TP-Link WR740 routers are vulnerable to a path traversal vulnerability on the web administration interface. Unauthenticated users are able to read any file from the device.
Informational June 14, 2012
Huawei HG866 authentication bypass
The web management interface of Huawei HG688 routers has several pages which fail to validate the user's session. This allows an attacker to bypass the authentication both locally and remotely.
Informational May 26, 2012
Netgear Information Disclosure
<p>Several NETGEAR devices are vulnerable to information disclosure via the web interface.</p>
Informational September 13, 2011
PHP Self Cross Site Scripting in MantisBT 1.2.x
MantisBT installations 1.2.x up to 1.2.7 are vulnerable to Cross Site Scripting attacks due to lack of sanitation of the variable $_SERVER["PHP_SELF"]
Informational August 23, 2011
Anti-CSRF Filter Bypass SMF 2.0 / 1.1.14
The [img] BBCode tag anti-CSRF filter can be bypassed due to incorrect parsing of the 'action' variable, because of this it is possible to execute CSRF successfully.
Informational May 29, 2010
Huawei EchoLife HG520 Remote Management CSRF
Huawei EchoLife HG520 modems do not require authentication to access certain pages such as: '/Forms/access_cwmp_1', '/Forms/rpQos_1' and '/Forms/rpRManage_1'. A CSRF exploit can be used to enable remote administration inerfaces on the WAN.