Debugging shell with root privileges in routers TP-Link WR740

Debugging shell with root privileges in routers TP-Link WR740

Posted on Jun 18 2012   |  Plain text version

Summary

There is a hidden debugging shell with root privileges in routers TP-Link WR740.

Description

Models: WDR740N, WDR740ND and possibly others
Update: People have been reporting on forums that models WR743ND,WR842ND,WA-901ND,WR941N,WR941ND,WR1043ND,WR2543ND,MR3220,MR3020,WR841N also have access to this root shell.
Firmware version: 3.12.11 Build 111130 Rel.55312n and possibly others
Date: 18/06/2012
Severity: High
Impact: Debugging shell with root privileges.
Attack vector: Local and remote.
Solution: N/A

TP-Link WDR740ND/WDR740N routers have a hidden debugging shell with root privileges that could be abused by attackers.

The username is hard coded in the HTTP server binary and the password cannot be changed from the management interface so the following credentials are almost guaranteed to work:

/userRpmNatDebugRpm26525557/linux_cmdline.html.

User:osteam
Password:5up

Using this shell attackers may add malicious routing rules or change configuration files.

POC

Go to http://ip/userRpmNatDebugRpm26525557/linux_cmdline.html and enter the credentials "osteam:5up"


Latest Blog Entries

Panoptic
An overview of Panoptic, an open source penetration testing tool that automates the process of search and retrieval of common log and config files through LFI vulnerabilities.
Posted in panoptic python tool lfi

Special discount code for "Nmap 6: Network Exploration and Security Auditing Cookbook"
PacktPub created a special discount code for our friends from HackerHalted
Posted in Nmap Hacker Halted nmap cookbook

Mac2WepKey HHG5xx for iPhone
The famous app to obtain the default WiFi passwords for Huawei routers is now available for the iPhone iOS 5.
Posted in HHG5xx iPhone huawei mac2wepkey passwords generator

Latest News

Oct 12, 2012
Websec at Hacker Halted USA 2012
Hacker Halted USA 2012 will reunite information security specialists from around the world to show the latest and most innovating research in the field of information security.

Sep 27, 2012
Nmap 6: Network Exploration and Security Auditing Cookbook is now on pre-sale!
The book "Nmap 6: Network Exploration and Security Auditing Cookbook" by Paulino Calderón is now on pre-sale and will be available soon.