Threat Level: green Handler on Duty: Manuel Humberto Santander Pelaez

SANS ISC: Linksys WAP610N has Unauthenticated Root Console issue SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms: https://isctv.sans.edu

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
Linksys WAP610N has Unauthenticated Root Console issue

Passed to the Internet Storm Center from Jim.

Linksys wireless access point (WAP610N) has an unauthenticated root console issue  

Taken from the actual advisory

*** SUMMARY ***

Linksys WAP610N is a SOHO wireless access point supporting 802.11n draft.

Unauthenticated remote textual administration console has been found that allow an attacker to run system command as root user.

Full details can be found here: http://www.securenetwork.it/ricerca/advisory/download/SN-2010-08.txt

This issue was also posted to the Full Disclosure mailing list http://seclists.org/fulldisclosure/2011/Feb/228

 

Chris Mohan --- ISC Handler on Duty

Chris

105 Posts
ISC Handler
wow, wide open.. I happened to have a few of these in my office new in the box. Just tested a direct telnet connection to 1111 and dropped into a UID0 shell, no password required.
Anonymous

Sign Up for Free or Log In to start participating in the conversation!