PT-2017-3191 · Mitrastar · Mitrastar Gpt-2541Gnac+1

Published

2017-10-28

·

Updated

2019-10-03

·

CVE-2017-16523

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MitraStar GPT-2541GNAC (HGU) version 1.00(VNJ0)b1 MitraStar DSL-100HN-T1 version ES 113WJY0b16
Description The issue is related to the use of a predefined account, specifically the zyad1234 account with the password zyad1234, which has privileges equivalent to root. This account is undocumented. Exploitation of this issue may allow a remote attacker to gain access to the device with root-equivalent privileges.
Recommendations For MitraStar GPT-2541GNAC (HGU) version 1.00(VNJ0)b1, consider changing the password of the zyad1234 account to prevent unauthorized access. For MitraStar DSL-100HN-T1 version ES 113WJY0b16, consider changing the password of the zyad1234 account to prevent unauthorized access. As a temporary workaround, consider disabling the zyad1234 account until a more permanent solution is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02616
CVE-2017-16523

Affected Products

Mitrastar Dsl-100Hn-T1
Mitrastar Gpt-2541Gnac