vendor:
DR-810
by:
SajjadBnd
N/A
CVSS
HIGH
File Disclosure
200
CWE
Product Name: DR-810
Affected Version From: DR-810
Affected Version To: DR-810
Patch Exists: NO
Related CWE:
CPE: a:across:dr-810
Platforms Tested: DR-810
2019
Across DR-810 ROM-0 Backup – File Disclosure(Sensitive Information)
A vulnerability exists in the DR-810 modem where the rom-0 file, which contains sensitive information including the router password, can be downloaded without authentication. By sending a simple GET request to the target address with /rom-0 appended, the file can be downloaded. The file can then be decompressed to obtain the password.
Mitigation:
The vendor should release a patch or firmware update to fix this vulnerability. In the meantime, users should ensure that their network devices are not accessible from the internet or restrict access to trusted IP addresses.