Exploits / Vulnerability Discovered : 2021-04-02 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Zbl epon onu broadband router 1.0 remote privilege escalation is for educational purposes only and if it is used you will do on your own risk!
Summary: EONU-x GEPON ONU layer-3 home gateway/CPE broadband
router.
Desc: The application suffers from a privilege escalation
vulnerability. The limited administrative user (admin:admin)
can elevate his/her privileges by sending a HTTP GET request
to the configuration backup endpoint or the password page
and disclose the http super user password. Once authenticated
as super, an attacker will be granted access to additional and
privileged functionalities.
Tested on: GoAhead-Webs/2.5.0 PeerSec-MatrixSSL/3.1.3-OPEN
Vulnerability discovered by Gjoko 'LiquidWorm' Krstic
@zeroscience