PT-2019-19276 · Dasan · Dasan H665
Krzysztof Burghardt
·
Publicado
2019-02-20
·
Atualizado
2024-02-23
·
CVE-2019-8950
CVSS v2.0
10
Crítica
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
DASAN H665 version 1.46p1-0028
Description
A backdoor account exists in the /bin/login of DASAN H665 devices, allowing an attacker to login to the admin account via TELNET using the account
dnsekakf2$$. This issue has seen increased interest, indicating potential exploitation.Recommendations
For DASAN H665 version 1.46p1-0028, consider disabling TELNET access to prevent exploitation of the backdoor account
dnsekakf2$$ until a patch is available. Restrict access to the admin account to minimize the risk of unauthorized login.Exploit
Correção
Using Hardcoded Credentials
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Dasan H665