vendor:
WiPG-1500
by:
Quentin Olagne
8,1
CVSS
HIGH
Manufacturer Backdoor Account
287
CWE
Product Name: WiPG-1500
Affected Version From: All versions of WiPG-1500 devices
Affected Version To: Latest firmware (1.0.3.7)
Patch Exists: NO
Related CWE: CVE-2017-6351
CPE: h:awind:wipg-1500
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Latest firmware (1.0.3.7)
2017
CVE-2017-6351 – WePresent undocumented privileged manufacturer backdoor account
WiPG-1500 device embeds a firmware with a manufacturer account with hard coded username / password. Once the device is set in DEBUG mode, an attacker can connect to the device using telnet protocol and log in the device with the 'abarco' hard-coded manufacturer account. This account is not documented, neither the DEBUG feature nor the use of telnetd on a port TCP/5885 (when debug mode is ON).
Mitigation:
Vendor has removed the 'abarco' account on the newest models but don't worry, DEBUG mode is still there with telnetd and you can also use the r00t account with a home and /bin/sh on the other systems in any case.