Bugtraq mailing list archives

Re: Asante FM2008 10/100 Ethernet switch backdoor login


From: secfocus2 () joe philipps us
Date: 24 Jul 2009 02:30:32 -0000

Asante have released v1.07 of this switch's firmware which removes the "superuser" "asante" CLI credentials.  After 
uploading this firmware into my switch, I examined a TFTP dump and could not identify similar credentials.  It does not 
positively rule in or out that the backdoor is gone, but Asante claim in their notes on the new firmware this back door 
has been removed.


Current thread: