vendor:
TC7200
by:
N/A
7,5
CVSS
HIGH
Insecure session management, Backup file encryption uses fix password
287
CWE
Product Name: TC7200
Affected Version From: STD6.02.11
Affected Version To: STD6.02.11
Patch Exists: NO
Related CWE: CVE-2014-1677
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
Technicolor TC7200 modem/router multiple vulnerabilities
The web interface does not use cookies at all and does not check the IP address of the client. If admin login is successful, every user from the LAN can access the management interface. Technicolor fixed the CVE-2014-1677 by encrypting the backup file with AES. However, the encrypted backup file remains accessible without authentication and if the password is not set in the web interface a default password is used. So, if an attacker accesses the backup file without authentication, the password cannot be set, and the backup file can be decrypted.
Mitigation:
Change the default passphrase.