Critical December 18, 2014
Command Execution and Backdoor in Zhone GPON-2520
This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.
High May 22, 2014
Huawei HG8245 / HG8247 WPA Generator
Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).
High December 19, 2013
Arbitrary Command Execution in Alcatel-Lucent I-240W-Q
The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.
Critical December 9, 2013
Huawei HG8245 backdoor and remote access
The Huawei HG8245 ONT, firmware version V1R006C00S100 which provides cellular services, contains 3 severe vulnerabilities: two administrator accounts enabled by default and a public administration interface exposed to the Internet.
Critical January 18, 2013
Multiple vulnerabilities in ZPanel 10.0.1
Several vulnerabilties were discovered in ZPanel 10.0.1 during our pro bono security audit. The ZPanel team has addressed these issues in version 10.0.2 and it is advised to upgrade.
Critical June 18, 2012
Debugging shell with root privileges in routers TP-Link WR740
A range of TP-Link WR740 and related models ship with a hidden debug shell running as root. The credentials are hard-coded in the HTTP server binary and cannot be changed, giving attackers reliable root-level access from the local network or, in some cases, remotely.
High June 17, 2012
Path traversal in TP-LINK WR740 and possibly others
TP-Link WR740 routers are vulnerable to a path traversal vulnerability on the web administration interface. Unauthenticated users are able to read any file from the device.
Critical June 14, 2012
Huawei HG866 authentication bypass
The web management interface of Huawei HG688 routers has several pages which fail to validate the user's session. This allows an attacker to bypass the authentication both locally and remotely.
Medium May 26, 2012
Netgear Information Disclosure
Several NETGEAR devices expose /currentsetting.htm without authentication, leaking the device model, firmware version, and other metadata that lets an attacker fingerprint the router before launching model-specific exploits.
Medium September 13, 2011
PHP Self Cross Site Scripting in MantisBT 1.2.x
MantisBT installations 1.2.x up to 1.2.7 are vulnerable to Cross Site Scripting attacks due to lack of sanitation of the variable $_SERVER["PHP_SELF"]
Medium August 23, 2011
Anti-CSRF Filter Bypass SMF 2.0 / 1.1.14
The [img] BBCode tag anti-CSRF filter can be bypassed due to incorrect parsing of the 'action' variable, because of this it is possible to execute CSRF successfully.
Critical May 29, 2010
Huawei EchoLife HG520 Remote Management CSRF
Huawei EchoLife HG520 modems do not require authentication to access certain pages such as: '/Forms/access_cwmp_1', '/Forms/rpQos_1' and '/Forms/rpRManage_1'. A CSRF exploit can be used to enable remote administration inerfaces on the WAN.