HomeRapidalertWeakness (default password) leads to breach of OTE modems Conn-X connections!

Weakness (default password) leads to breach of OTE modems Conn-X connections!

ote-root-001

The well-known security forum P0wnbox has started operating again!! SecNews has identified a particularly interesting article-guide on the existence of a vulnerability in the well-known Huawei modems that OTE provides with Conn-X connections.

Read the details below:

The Huawei HG-530 modem/router is one of the modems that OTE provides along with an OTENet Conn-X connection.

This is installed on the internal IP 192.168.1.1

Like all others of its kind, this device has a Linux operating system, only it is a little locked down. And I say “a little” because with very little effort, someone can unlock it and even root this device.

Someone will ask themselves,… So what?

What can I tell you... from the moment you root such a device, you can do... whatever you want (no more, no less). B)

The first test I did was to check this IP with the classic nmap (ZenMap to be exact).

ote-root-002

Hmm,.. I see several interesting services running here:

I focus first on port 22. That's where the ssh (Secure SHell) service runs.

I'll try to open a connection via PuTTY. To see how easy it is:

ote-root-003

No matter how much good will I have, I'm stuck at this door (22). What other alternatives do I have?

Hmm, I saw that port 23 (telnet) is also open, I have nothing to lose by trying from there.

ote-root-003-0

Yes! This is a good start. The question now is what is the login/password. As a first classic approach to the problem I try the well-known one for OTE devices (and not only)
Login: admin
Password: admin

My choice seems to have paid off:

ote-root-004

I entered the ATP . It's not the easiest modem management environment to use. The classic "?" command gives me very few commands available, and it doesn't seem like I can do much with it.

this link states that there are other commands than the ones it supposedly says my modem supports.

One of them is the “shell” command… Let me give it to see what happens…

ote-root-005

Welcome to root!
Hmm… Yes!! It was SO easy.

I can now try some other commands mentioned in the link above:

ote-root-006As well as some other more… linux:

ote-root-007

What else can I do now..

just test and try... the choice is yours!

 

Source: p0wnbox.com

SecNews Note: The existence of a default admin password can indeed be used to install a unix-based backdoor on the modem (precompiled). It must be examined IMMEDIATELY by network service providers (e.g. OTE) in collaboration with the equipment vendor (Huawei) to see if it is possible to “lock” the modem (preconfigured random pass) they provide to their customers in order to ensure that this vulnerability is not used by malicious users. It is also worth mentioning that the modem stores the username and password of the user to the provider, in Plaintext format that the respective malicious attacker can extract with particular ease.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS