Alcatel Speed Touch ADSL Insecure...

- AV AC AU C I A
发布: 2001-04-10
修订: 2025-04-13

In the factory shipped state, no password is set for the device's administration interface. This could permit a user to reconfigure the unit, or set the password and prevent the device from being reconfigured. Once a password has been set, the device remains vulnerable to attack in two ways. - TFTP: The device's TFTP service can be used to overwrite configuration files. This approach may allow an attacker to set or modify the administration password even if it has been previously set. - Cryptographic attack: by connecting to the "EXPERT" account, a challenge-response sequence is initiated which is reportedly vulnerable to cryptographic attack. Details of the challenge-response algorithm were not made publicly available. The device's configuration settings are accessible through FTP, HTTP and Telnet interfaces. In addition, the device's file structure is exposed through FTP. All of these services allow the modification of configuration information. By default, no password is set for...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息