vendor:
GPON/EPON OLT Platform
by:
LiquidWorm
8.8
CVSS
HIGH
Unauthenticated Configuration Download and Information Disclosure
200
CWE
Product Name: GPON/EPON OLT Platform
Affected Version From: V2.03.62R_IPv6
Affected Version To: V1.4
Patch Exists: YES
Related CWE: N/A
CPE: h:guangzhou_v-solution_electronic_technology:gpon/epon_olt_platform
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: GoAhead-Webs
2019
V-SOL GPON/EPON OLT Platform 2.03 – Unauthenticated Configuration Download
The device OLT Web Management Interface is vulnerable to unauthenticated configuration download and information disclosure vulnerability when direct object reference is made to the usrcfg.conf file using an HTTP GET method. This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.
Mitigation:
Ensure that the device is not exposed to the public internet and is behind a firewall. Ensure that the device is running the latest version of the firmware.