domingo, 28 de abril de 2024

Weak Remote Telnet Access at PIX-LINK LV-WR07 ("CVE requested")

 

Report Vulnerability

Product: PIX-LINK
Model: LV-WR07
Vulnerability: Weak Remote Telnet Access
Impact: This allows an attacker to gain root access to the device over the local network.
Author: Red Team ~ Fabrício Oliveira (xf5), Miguel Alves (@0xmupa), Sérgio Charruadas;

PoC

The router has a weak connection with the telnet protocol. Using the password "admin:admin" allows connection to a remote router like an administrator.


There are command examples to down the router through SPI write memory.





Nenhum comentário:

Postar um comentário