vendor:
My Net Series Wireless Routers
by:
N/A
4,3
CVSS
MEDIUM
Plaintext Storage of a Password
256
CWE
Product Name: My Net Series Wireless Routers
Affected Version From: 1.03.12
Affected Version To: 1.06.28
Patch Exists: NO
Related CWE: CVE-2013-5006
CPE: h:western_digital:my_net_series_wireless_routers
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2013
Western Digital My Net Series Wireless Routers Vulnerability
By sending a specially crafted command to the affected routers, the clear text password for the admin account can be extracted, with no authentication required to access the page where it is stored. During the initial setup of these four routers with the affected firmware, the admin password is stored in clear text on the main_internet.php? source code page as the value for 'var pass'. For this bug to exploitable from a remote network attack, UPnP and remote administrative access (port 8080 is set by default) must be enabled.
Mitigation:
Disable UPnP and remote administrative access (port 8080) to prevent exploitation.