vendor:
2Wire Gateway
by:
Unknown
5.5
CVSS
MEDIUM
Authentication Bypass & Password Reset
287
CWE
Product Name: 2Wire Gateway
Affected Version From: 5.29.51, 3.17.5, 3.7.1
Affected Version To:
Patch Exists: YES
Related CWE:
CPE: a:2wire:2071_gateway, cpe:/a:2wire:1800hw, cpe:/a:2wire:1701hg
Platforms Tested:
2009
2WIRE GATEWAY AUTHENTICATION BYPASS & PASSWORD RESET
There is an authentication bypass vulnerability in page=CD35_SETUP_01 that allows you to set a new password even if the password was previously set. By setting a new password with more than 512 characters, the password gets reset and next time you access the router you will be prompted for a new password.
Mitigation:
Upgrade to firmware version 5.29.135.5 or later