vendor:
ADSL Router
by:
Todor Donev
7,5
CVSS
HIGH
Unauthenticated Remote DNS Change
N/A
CWE
Product Name: ADSL Router
Affected Version From: CT-5367 C01_R12, CT-5624 C01_R03
Affected Version To: CT-5367 C01_R12, CT-5624 C01_R03
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2016
COMTREND ADSL Router CT-5367 C01_R12, CT-5624 C01_R03 Unauthenticated Remote DNS Change Exploit
The vulnerability exist in the web interface, which is accessible without authentication. Once modified, systems use foreign DNS servers, which are usually set up by cybercriminals. Users with vulnerable systems or devices who try to access certain sites are instead redirected to possibly malicious sites. Modifying systems' DNS settings allows cybercriminals to perform malicious activities like steering unknowing users to bad sites, replacing ads on legitimate sites, controlling and redirecting network traffic, and pushing additional malware.
Mitigation:
Authentication should be enabled for the web interface.