Latest YouTube Video

Friday, September 29, 2017

[FD] Zyxel P-2812HNU-F1 DSL router - command injection

Zyxel P-2812HNU-F1 DSL router - command injection ================================================= The Zyxel P-2812 is common in the Netherlands (KPN/Telfort) and Norway (Telenor). The Dutch firmware is susceptible to authenticated command injection through `qos_queue_add.cgi` and the `WebQueueInterface` parameter. Affected firmware versions ========================== V3.11TUE3 (KPN) V3.11TUE8 (KPN) Not affected ============ BLN.18 and up (Telenor) Disclosure timeline =================== 2017-02-05 Notified cert@kpn-cert.nl 2017-02-11 Notified cert@telenor.net 2017-02-15 KPN: "escalated to Zyxel" 2017-02-23 Telenor: "we have fixed this previously in BLN18" 2017-09-28 Public disclosure Proof of concept code ===================== Sample code at http://ift.tt/2x1ACmQ Observations ============ Security fixes for branded Zyxel firmware are not necessarily implemented by all OEM clients.

Source: Gmail -> IFTTT-> Blogger

No comments: