vendor:
DT-100G-N, DT-300N, CW-300N, Kozumi?
by:
N/A
8,8
CVSS
HIGH
Command Injection, Information Disclosure, Hard-coded and Default Credentials, Hidden Backdoors
78, 200, 287, 522
CWE
Product Name: DT-100G-N, DT-300N, CW-300N, Kozumi?
Affected Version From: Cen-WR-G2H5 v1.0.6
Affected Version To: Cen-CPE-N5H5R v1.1.1
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020
CERIO 11nbg 2.4Ghz High Power Wireless Router (pekcmd) Rootshell Backdoors
Cerio Wireless Access Point and Router suffers from several vulnerabilities including: hard-coded and default credentials, information disclosure, command injection and hidden backdoors that allows escaping the restricted shell into a root shell via the 'pekcmd' binary. Given that all the processes run as root, an attacker can easily drop into the root shell with supplying hard-coded strings stored in .rodata segment assigned as static constant variables. The pekcmd shell has several hidden commands that can be used to gain root access.
Mitigation:
Ensure that all default credentials are changed, disable unnecessary services, and restrict access to the device to only trusted users.