Alcatel Speed Touch Pro ADSL...

- AV AC AU C I A
发布: 2001-04-10
修订: 2025-04-13

The Alcatel Speed Touch family of ADSL-Ethernet router/bridge products exhibit several serious security flaws. Certain Alcatel ADSL-Ethernet bridge products feature an embedded TFTP server which can be used by remote users to make changes to configuration and firmware. Normally, the TFTP service in such a device would not be accessible from the WAN. In this case, however, the interface is available to both extranet users and attackers local to the copper loop on which the DSL connection is carried. Since TFTP provides no support for user authentication, this leaves the device's admin interface and firmware upload feature completely open to any attacker. Moreover, user-supplied firmware code transferred to the router/bridge is not checked for authenticity, and an attacker may exploit the open TFTP interface to install malicious code on the device. No method is available for disabling the vulnerable TFTP service. *** NOTE: Shortly after this advisory was published, the vendor,...

0%
暂无可用Exp或PoC
当前有0条受影响产品信息