header-logo
Suggest Exploit
vendor:
ZXDSL 831 II
by:
SuNHouSe2
7,5
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: ZXDSL 831 II
Affected Version From: ZXDSL 831IIV7.5.0a_E09_OV
Affected Version To: ZXDSL 831IIV7.5.0a_E09_OV
Patch Exists: NO
Related CWE: N/A
CPE: h:zte:zxdsl_831_ii
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

ZTE CORPORATION ADSL Modem ZXDSL 831 II Exploit

This modem is used by many providers in the world like russia india and algeria [used by provider and all clients of 'Easy ADSL']. We can change easily the user and password admin and get full access to the modem. Go only here and set new user and password: http://192.168.1.1/adminpasswd.cgi

Mitigation:

Ensure that authentication credentials are properly configured and that access to the modem is restricted to authorized personnel only.
Source

Exploit-DB raw data:

-----------------------------------------------------
    -->> Found By  SuNHouSe2 [ALGERIAN HaCkEr] <<--
           --> Made in "Maghnia City" (DZ) <--
          --> Contact : sunhouse2@yahoo.com <--
        --> Greetz to : His0k4 all my friends <--
          --> Good Ramadan to all muslims <--
-----------------------------------------------------

Exploit tested on modem with this informations :

ZTE CORPORATION

Date             : NOV 2008
Product          : ADSL Modem
Model            : ZXDSL 831 II --> http://www.geeksecurity.org/tsttte.JPG
Firmware Version : ZXDSL 831IIV7.5.0a_E09_OV
 
-----------------------------------------------------
Introduction:

This modem is used by many providers in the world like 
russia india and algeria [used by provider and all clients of "Easy ADSL"].

Exploit :
We can change easily the user and password admin and get full access to the modem.

Go only here  and set new user and password:

http://192.168.1.1/adminpasswd.cgi

# milw0rm.com [2009-08-18]