ID

VAR-201106-0317


TITLE

MODACOM URoad-5000 Security Bypass Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2011-2089

DESCRIPTION

The MODACOM URoad-5000 is a portable WiMAX/WiFi router. The MODACOM URoad-5000 device uses the modified RaLink SDK version to access standard web interfaces via HTTP. The WEB management interface can be accessed by admin:admin via a standard username/password, which can be changed later. But there is another engineer:engineer pair can also be changed by the WEB interface. MODACOM URoad-5000 is prone to a security-bypass vulnerability and a remote command-execution vulnerability. An attacker can exploit these issues to bypass certain security restrictions and execute arbitrary commands on the affected device. MODACOM URoad-5000 firmware version 1450 is vulnerable; other versions may also be affected

Trust: 1.35

sources: CNVD: CNVD-2011-2089 // CNVD: CNVD-2011-2091 // BID: 48089

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 1.2

sources: CNVD: CNVD-2011-2089 // CNVD: CNVD-2011-2091

AFFECTED PRODUCTS

vendor:modacommodel:uroad-5000scope:eqversion:1450

Trust: 1.5

sources: CNVD: CNVD-2011-2089 // CNVD: CNVD-2011-2091 // BID: 48089

THREAT TYPE

local

Trust: 0.3

sources: BID: 48089

TYPE

Design Error

Trust: 0.3

sources: BID: 48089

EXTERNAL IDS

db:BIDid:48089

Trust: 1.5

db:EXPLOIT-DBid:17356

Trust: 1.2

db:CNVDid:CNVD-2011-2089

Trust: 0.6

db:CNVDid:CNVD-2011-2091

Trust: 0.6

sources: CNVD: CNVD-2011-2089 // CNVD: CNVD-2011-2091 // BID: 48089

REFERENCES

url:http://www.exploit-db.com/exploits/17356/

Trust: 1.2

url:http://www.modacom.co.kr

Trust: 0.3

sources: CNVD: CNVD-2011-2089 // CNVD: CNVD-2011-2091 // BID: 48089

CREDITS

Alex Stanev

Trust: 0.3

sources: BID: 48089

SOURCES

db:CNVDid:CNVD-2011-2089
db:CNVDid:CNVD-2011-2091
db:BIDid:48089

LAST UPDATE DATE

2022-05-17T01:46:44.578000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2011-2089date:2011-06-03T00:00:00
db:CNVDid:CNVD-2011-2091date:2011-06-03T00:00:00
db:BIDid:48089date:2011-06-02T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2011-2089date:2011-06-03T00:00:00
db:CNVDid:CNVD-2011-2091date:2011-06-03T00:00:00
db:BIDid:48089date:2011-06-02T00:00:00