vendor:
ZXV10 W300
by:
Karn Ganeshen
8,8
CVSS
HIGH
Insufficient authorization controls, Sensitive information disclosure - clear-text passwords, (Potential) Backdoor account feature - insecure account management
287, 200, 522
CWE
Product Name: ZXV10 W300
Affected Version From: W300V2.1.0f_ER7_PE_O57
Affected Version To: W300V2.1.0h_ER7_PE_O57
Patch Exists: YES
Related CWE: CVE-2015-7257, CVE-2015-7258, CVE-2015-7259
CPE: 2.3:o:zte:zxv10_w300:2.1.0f_er7_pe_o57, 2.3:o:zte:zxv10_w300:2.1.0h_er7_pe_o57
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
ZTE ADSL ZXV10 W300 modems – Multiple vulnerabilities
Any non-admin user can change 'admin' password by accessing Password Change page - http://<IP>/password.htm and submitting request. Intercept and Tamper the parameter username change from 'support' to 'admin' and enter the new password. Also, displaying user information over Telnet connection, shows all valid users and their passwords in clear-text. Same login account can exist on the device, multiple times, each with different priority#. It is possible to log in to device with either of the username/password combination.
Mitigation:
Enforce strong authentication and authorization controls. Use secure protocols for communication. Use encryption for sensitive data.