Netopia 650-T ISDN Router Username/Password Disclosure Vulnerability

A vulnerability exists in the Netopia 650-ST ISDN router, firmware version 3.3.2.

A user connected to the unit's telnet interface can cause the device's system logs to be displayed with a simple keystroke entered by the user at the login screen.

[CTRL]-E - displays the device event log
[CTRL]-F - displays the WAN event log.

Access to this information by a malicious remote user can lead to a compromise of sensitive information including usernames and passwords.


 

Privacy Statement
Copyright 2010, SecurityFocus