ID

VAR-200804-0458


TITLE

Thomson SpeedTouch and BT Home Hub Router Default WEP/WPA Key Algorithm Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2008-2093

DESCRIPTION

Both BT Home Hub and Speedtouch are home wireless Internet routers. The default WEP/WPA key algorithm used by BT Home Hub and Speedtouch routers is predictable, and remote attackers can predict keys based on some public information (such as MAC address or SSID) so that they can completely invade the router. For Speedtouch router router: S/N: CP0615JT109 (53) Delete CC and PP values: CP0615109 converts XXX value to hexadecimal: CP0615313039 through SHA-1 processing: 742da831d2b657fa53d347301ec610e1ebf8a3d0 converts the last 3 bytes into 6-byte characters The string, then added to SpeedTouch, becomes the default SSID: SpeedTouchF8A3D0 converts the first 5 bytes into a 10-byte string and becomes the default WEP/WPA key: 742DA831D2 for BT Home Hub, the only difference is Use the last 2 bytes of the SHA1 hash to get the SSID: S/N: CP0647EH6DM (BF) Delete CC and PP values: CP06476DM16 encoding XXX: CP064736444DSHA1 encryption: 06f48a28eba1ab896a396077d772fd65503b8df3 Default SSID: BTHomeHub-8DF3 default encryption key: 06f48a28eb. Multiple wireless routers are prone to a vulnerability that can allow an attacker to predict their default WEP/WPA encryption keys. Attackers can exploit this issue to bypass authentication to an affected device, which can allow them to completely compromise the device or to gain access to the private network

Trust: 0.81

sources: CNVD: CNVD-2008-2093 // BID: 28893

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2008-2093

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

vendor:thomsonmodel:speedtouchscope:eqversion:0

Trust: 0.3

vendor:btmodel:home hubscope:eqversion:0

Trust: 0.3

sources: CNVD: CNVD-2008-2093 // BID: 28893

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2008-2093
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2008-2093
severity: MEDIUM
baseScore: 4.3
vectorString: AV:N/AC:M/AU:N/C:N/I:P/A:N
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: NONE
exploitabilityScore: 8.6
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2008-2093

THREAT TYPE

network

Trust: 0.3

sources: BID: 28893

TYPE

Design Error

Trust: 0.3

sources: BID: 28893

EXTERNAL IDS

db:BIDid:28893

Trust: 0.9

db:CNVDid:CNVD-2008-2093

Trust: 0.6

sources: CNVD: CNVD-2008-2093 // BID: 28893

REFERENCES

url:http://marc.info/?l=bugtraq&m=120890136725340&w=2

Trust: 0.6

url:http://www.homehub.bt.com/

Trust: 0.3

url:http://www.gnucitizen.org/blog/default-key-algorithm-in-thomson-and-bt-home-hub-routers/

Trust: 0.3

url:http://www.thomson-broadband.co.uk/codepages/content.asp?c=1

Trust: 0.3

url:/archive/1/491206

Trust: 0.3

sources: CNVD: CNVD-2008-2093 // BID: 28893

CREDITS

Kevin Devine

Trust: 0.3

sources: BID: 28893

SOURCES

db:CNVDid:CNVD-2008-2093
db:BIDid:28893

LAST UPDATE DATE

2022-05-17T01:56:45.983000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2008-2093date:2014-01-24T00:00:00
db:BIDid:28893date:2008-04-23T16:47:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2008-2093date:2008-04-22T00:00:00
db:BIDid:28893date:2008-04-22T00:00:00