Skip to main content
High November 1, 2009

2Wire Remote Denial of Service

The remote management interface on tcp/50001 of various 2Wire devices suffer from a remote denial of service vulnerability.

CVSS Score

7.5 / 10.0

Severity

High

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Advisory

Device2Wire Gateway Router / Modem
Vulnerable Versions< 5.29.52
Vulnerable Models1700HG, 1701HG, 1800HW, 2071, 2700HG, 2701HG-T
ImpactUnauthenticated remote reboot
LocationRemote management interface, tcp/50001
Websec AdvisoryWS103

Background

Some 2Wire modems enable the remote management interface by default. The interface listens on tcp/50001 over SSL, with an untrusted issuer certificate.

Description

Requesting a specially formed URL against the remote management interface reboots the device. No authentication is required, so any internet client that can reach tcp/50001 can trigger the reboot.

Exploit / Proof of Concept

https://<device-ip>:50001/xslt?page=%0d%0a

Workaround

Disable Remote Management under Firewall → Advanced Settings on the device web UI. Vendor firmware 5.29.52 or later addresses the underlying issue; providers are responsible for rolling out the patch.

Remediation

Apply vendor firmware 5.29.52 or later. ISPs control patch rollout for provider-managed devices.

Share this advisory:

Related Security Advisories

Stay informed about other recent vulnerabilities and security advisories

Critical December 18, 2014

Command Execution and Backdoor in Zhone GPON-2520

This post will describe a backdoor account found in the Zhone GPON-2520 and will provide a PoC which can be used to disable the firewall filtration rules in order to allow access to services such as ssh, telnet and ftp.

Severity:
CVSS: 9.8
View advisory
High May 22, 2014

Huawei HG8245 / HG8247 WPA Generator

Huawei HG8245 & HG8247 ONT (firmware version V1R006C00S100) rely on a weak algorithm to calculate the WPA keys, keys can be predicted easily using the WiFi's MAC Address (BSSID).

Severity:
CVSS: 7.4
View advisory
High December 19, 2013

Arbitrary Command Execution in Alcatel-Lucent I-240W-Q

The Alcatel-Lucent I-240W-Q ONT's Diagnostics page does not filter shell metacharacters in the IP address field, allowing any authenticated administrator to execute arbitrary commands as root and fully compromise the device.

Severity:
CVSS: 8.0
View advisory