vendor:
G150R-V1, G300R-V1, N150RH-V1, N301RT-V1
by:
Pierre Kim
7.5
CVSS
HIGH
Backdoor credentials
798
CWE
Product Name: G150R-V1, G300R-V1, N150RH-V1, N301RT-V1
Affected Version From: 1.0.0-B20150330
Affected Version To: 1.0.0
Patch Exists: Yes
Related CWE: No current CVE
CPE: h:totolink:g150r-v1
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Backdoor credentials found in 4 TOTOLINK router models
Backdoor credentials are present in several TOTOLINK products. It affects 4 TOTOLINK products (firmwares come from totolink.net and from totolink.cn): G150R-V1 : last firmware 1.0.0-B20150330 (TOTOLINK-G150R-V1.0.0-B20150330.1734.web) G300R-V1 : last firmware 1.0.0-B20150330 (TOTOLINK-G300R-V1.0.0-B20150330.1816.web) N150RH-V1 : last firmware 1.0.0-B20131219 (TOTOLINK-N150RH-V1.0.0-B20131219.1014.web) N301RT-V1 : last firmware 1.0.0 (TOTOLINK N301RT_V1.0.0.web). It allows an attacker in the LAN to connect to the device using telnet with 2 different accounts: root and 'onlime_r' which gives with root privileges.
Mitigation:
Users should update their firmware to the latest version available from the vendor.