[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Full-disclosure] ELSA Lancom Router Discloses the Administrator Password to Remote Users



> 
> It is reported that the default configuration allows a remote user to 
> connect to the router via port 80 with a web browser and obtain the remote 
> access password, which is apparently stored in clear text. The remote user 
> can also change the router's configuration and can remotely upgrade the 
> firmware. 
> 
 *Impact:* A remote user can obtain the administrator password, change 
routing tables, and upload modified firmware.
  *Solution:* No solution was available at the time of this entry.

The author of the report has provided the following recommendations:

- Change the configuration port. 
- Give access privileges during initial configuration to only internal ip 
addresses.
- Install a firewall with appropriate rules.

 Does anyone know how to get this P/W?
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/