vendor:
VMG3312-B10B
by:
numan türle
8.8
CVSS
HIGH
Credential Leakage
200
CWE
Product Name: VMG3312-B10B
Affected Version From: 1.00(AAPP.0)D7
Affected Version To: 1.00(AAPP.7)
Patch Exists: YES
Related CWE: N/A
CPE: h:zyxel:vmg3312-b10b
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2018
ZyXEL VMG3312-B10B – Leak Credentials < 1.00(AAPP.7)
A vulnerability in ZyXEL VMG3312-B10B firmware version 1.00(AAPP.0)D7 allows an attacker to gain access to the modem's FTP server using the credentials 'support' and 'support'. By downloading the file '/var/csamu' from the FTP server, an attacker can gain access to the credentials of all users of the modem. The credentials are stored in the file in base64 encoded format.
Mitigation:
Upgrade to the latest version of the firmware (1.00(AAPP.7))