PT-2019-8308 · Billion · Billion 5200W-T
Pedro Ribeiro
·
Published
2019-05-02
·
Updated
2019-05-03
·
CVE-2017-18373
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Billion 5200W-T TCLinux Fw version $7.3.8.0 v008 130603
Description
The issue concerns default passwords for three user accounts, including two hardcoded service accounts. One account has the username
true and password true, and another has the username user3 with a long password consisting of a repetition of the string 0123456789. These accounts can be used to login to the web interface, allowing for authenticated command injections and changes to router settings for malicious purposes.Recommendations
For Billion 5200W-T TCLinux Fw version $7.3.8.0 v008 130603, change the default passwords of the
true and user3 accounts to secure passwords to prevent unauthorized access. As a temporary workaround, consider restricting access to the web interface until the default passwords are changed.Exploit
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Billion 5200W-T