vendor:
EONU-x GEPON ONU layer-3 home gateway/CPE broadband router.
by:
LiquidWorm
7.5
CVSS
HIGH
Remote Privilege Escalation
CWE
Product Name: EONU-x GEPON ONU layer-3 home gateway/CPE broadband router.
Affected Version From: Firmwre: V100R001, Software model: HG104B-ZG-E / EONU-7114 / ZBL5932C CATV+PON Triple CPE, EONU Hardware Version V3.0, Software: V2.46.02P6T5S, Main Chip: RTL9607
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: GoAhead-Webs/2.5.0 PeerSec-MatrixSSL/3.1.3-OPEN
2021
ZBL EPON ONU Broadband Router 1.0 – Remote Privilege Escalation
The limited administrative user (admin:admin) can elevate his/her privileges by sending a HTTP GET request to the configuration backup endpoint or the password page and disclose the http super user password. Once authenticated as super, an attacker will be granted access to additional and privileged functionalities.
Mitigation:
Unknown