Skip to main content
Blog

Backdoor In Optical Fiber Device Alcatel-Lucent

The newest optical fiber devices offered by the ISP Infinitum have a backdoor which allow for full administration of these devices. This backdoor account is hidden by nature and does not allow for the password to be changed.

Share this article:
Backdoor In Optical Fiber Device Alcatel-Lucent

I was looking for a way to generate wireless password in Infinitum's new optical fiber devices when I happened to come across with an administration account with a static password which allows for full administration of the device.

This account is hidden and the password cannot be changed - a typical backdoor. After looking around a bit on the Internet, I noticed that his account is available on multiple devices.

The backdoor uses the following credentials:

User: telecomadmin
Password: nE7jA%5m
 

Here is the configuration file of the web authentication portal of the device which contains the backdoor account. You can see that the typical user account "TELMEX" has a password which was automatically generated (same password for WPA) and the backdoor account does not appear on the administration list of the device.



Enjoy your day.


* This post was originally written by Pedro Joaquin and translated by Roberto Salgado. The original post in Spanish can be found here.

Follow our research

Get new articles and security advisories as soon as they are published.

Related Articles

Discover more cybersecurity insights and solutions to help strengthen your organization's security posture

A Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalation
Blog

A Comparison Between the Real User ID and the Effective User ID is not Enough to Prevent Privilege Escalation

In Unix-like systems, processes have a real and effective user ID determining their access permissions. While usually identical, they can differ in situations like when the setuid bit is activated in executables.

Websec DevSecOps Webinar
Blog

Websec DevSecOps Webinar

Roberto Salgado and Kobalt.io's Miki Fukushima are hosting a free webinar on September 20, 2022 covering why application security matters, the shift to developer-first security, and a practical roadmap for embedding security into DevSecOps.

CVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQL
Blog

CVE-2022-21404: Another story of developers fixing vulnerabilities unknowingly because of CodeQL

How CodeQL may help reduce false negatives within Open-Source projects. Taking a look into a deserialization vulnerability within Oracle Helidon (CVE-2022-21404).