vendor:
H64X Series
by:
Gjoko 'LiquidWorm' Krstic
8,8
CVSS
HIGH
Authentication Bypass, Privilege Escalation and/or Full System Access
N/A
CWE
Product Name: H64X Series
Affected Version From: 2.45-1045
Affected Version To: 3.02p2-1141
Patch Exists: YES
Related CWE: N/A
CPE: h:dasan_networks:h64x_series
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Server: lighttpd/1.4.31, Server: DasanNetwork Solution
2017
Dasan Networks GPON ONT WiFi Router H64X Series System Config Download
The system backup configuration file 'running.CFG' and the wireless backup configuration file 'wifi.CFG' can be downloaded by an attacker from the root directory in certain circumstances. This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.
Mitigation:
Upgrade to the latest version of the firmware (3.03x) which is not affected by this issue.