vendor:
ZXV10 W300
by:
Osanda Malith Jayathissa
7,5
CVSS
HIGH
Default Password Being Used, ROM-0 Backup File Disclosure, PPPoE/PPPoA Password Disclosure in tc2wanfun.js
200, 255, 532
CWE
Product Name: ZXV10 W300
Affected Version From: W300V1.0.0a_ZRD_LK
Affected Version To: W300V1.0.0a_ZRD_LK
Patch Exists: YES
Related CWE: CVE-2014-4018, CVE-2014-4019, CVE-2014-4154
CPE: h:zte:zxv10_w300
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Kali Linux x86_64
2014
ZTE WXV10 W300 Multiple Vulnerabilities
In ZTE routers the username is a constant which is 'admin' and the password by default is 'admin'. The rom-0 backup file contains sensitive information such as the router password. There is a disclosure in which anyone can download that file without any authentication by a simple GET request. If you look at the frame source in the 'Internet' tab under the 'Interface Setup' you can see this doLoad function in line 542 which fetches the password and displays it there. The frame URI is /basic/home_wan.htm. Once the user authenticates the router till another succeful authentication the password will be displayed in the page.
Mitigation:
Ensure that the default password is changed and that the router is updated to the latest firmware version.