PT-2024-5339 · Joyent+1 · Smartos+1
Edward Warren
·
Published
2024-04-08
·
Updated
2024-09-03
·
CVE-2024-39345
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
AdTran 834-5 HDC17600021F1 (SmartOS) versions 11.1.1.1 through 12.5.5.0
Description
The issue concerns a hidden, undocumented, hard-coded support account in AdTran 834-5 devices, whose password is based on the device's MAC address. Since all internet interfaces share a similar MAC address that only varies in the final octet, network-adjacent attackers can derive the support user's SSH password by decrementing the final octet of the connected gateway address or via the BSSID. This allows attackers to execute arbitrary OS commands with root-level privileges.
Recommendations
For versions prior to 12.5.5.1, update to SmartOS 12.5.5.1 to resolve the issue.
As a temporary workaround, consider disabling the SSH service until a patch is available.
Restrict access to the device's internet interfaces to minimize the risk of exploitation.
Avoid using the default support account until the issue is resolved.
Exploit
Fix
Using Hardcoded Credentials
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Adtran 834-5
Smartos