Results 1 to 8 of 8

Thread: Security bug in ZXDSL 531B

  1. #1
    Junior Member
    Join Date
    Sep 2008
    Posts
    5

    Default Security bug in ZXDSL 531B

    If you are using BSNL's ZTE ZXDSL 531B to surf the net this post is for you.

    If you have not bothered to change the admin password, LAN IP of your modem, then you don't care enough - safely skip this post as this critical bug will be just another jump of convinience over security for you.

    I was fiddling with the tftp implementation of the modem which means I was trying to configure the modem from command line using

    telnet modem_ip 23

    on my ubuntu box. To my surprise, the user "user" which has limited rights of just uploading a new configuration file could do everything an "admin" could do from the telnet session. I have reported the bug to ZTE. Hopefully, they should upgrade their firmware with the fix.

    Those of you guys who changed the admin password but did not do the same with the "user" and "support" password - change it now.

  2. #2
    Platinum Member
    Join Date
    Feb 2008
    Posts
    2,766

    Default

    good job.. thanks for informing!!

  3. #3
    Admin's Avatar
    Join Date
    Jan 2006
    Posts
    5,833

    Default

    Thanks for sharing the info... this is like leaving one side of the house without fence and hoping that no one would ever notice it.

    Reps added.

  4. #4
    Platinum Member
    Join Date
    Feb 2008
    Posts
    2,766

    Default

    just tried it out with my modem also, same result.."user" can do anything via telnet but is limited when accessed via browser..My modem is ut300r2u.Very interesting.. although luckily i have disabled telnet access from the internet

  5. #5
    Bronze Member
    Join Date
    Sep 2008
    Posts
    140

    Default

    Thanks for informing and also sharing the content.This is the first time i had got information about telnet operations.

  6. #6
    Guardian Angel just4kix's Avatar
    Join Date
    Dec 2007
    Posts
    10,871

    Default

    Excellent pointer. Repo points given.

  7. #7
    Junior Member
    Join Date
    Sep 2008
    Posts
    5

    Default

    Quote Originally Posted by superprash2003 View Post
    just tried it out with my modem also, same result.."user" can do anything via telnet but is limited when accessed via browser..My modem is ut300r2u.Very interesting.. although luckily i have disabled telnet access from the internet
    I hope you have checked out the modem manufacturer's website on google and reported this bug to him.

    Quote Originally Posted by crashpoint_zero View Post
    I hope you have checked out the modem manufacturer's website on google and reported this bug to him.
    unless it is ZTE, of course. That would make both of us eligible for the prize money. : )
    Last edited by crashpoint_zero; 10-02-08 at 12:46 AM. Reason: Automerged Doublepost

  8. #8
    Junior Member NoisySilence's Avatar
    Join Date
    Feb 2009
    Age
    25
    Posts
    20

    Exclamation Yet another bug

    Recently, I was configuring my modem when I came up with this bug.

    In order to reboot your modem/router, one does not even need user privileges. Try this yourself

    type http://192.168.1.1/rebootinfo.cgi (change IP to your modem IP) and open it.

    Your modem will just reboot. No questions asked. So, if you haven't secured your modem, especially wifi, you are exposed to really a big problem.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. 10 Security Tips when using Cyber Cafes
    By itsmemad in forum Computer Security
    Replies: 15
    Last Post: 05-17-10, 10:01 AM
  2. Acronis Security Solution
    By meetdilip in forum Software News, Previews and Reviews
    Replies: 2
    Last Post: 02-14-10, 08:31 PM
  3. Online Security
    By Preeti_20 in forum Computer Security
    Replies: 3
    Last Post: 02-04-10, 12:15 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •