发布时间 :2004-10-26 00:00:00
修订时间 :2016-10-17 22:58:09

[原文]The Hawking Technologies HAR11A modem/router allows remote attackers to obtain sensitive information by connecting to port 254, which displays a management interface and information on established connections.

Hawking Technologies HAR11A路由器敏感信息泄露漏洞(CNNVD-200410-099)

        Hawking Technologies HAR11A是一款小型路由器。
        Hawking Technologies HAR11A存在未公开接口,远程攻击者可以利用这个接口控制路由器。

        Hawking Technology

Hawking HAR11A and HAR14A Router Unauthenticated Administrative Access
Remote / Network Access Authentication Management
Loss of Confidentiality
Exploit Public

ADSL Modem Router HAR11A and 4-port ADSL Modem Router HAR14A contain a flaw that may allow an attacker to obtain access to the router's administrative interface. The issue is triggered when the attacker uses telnet to connect to port 23, 254, or 255. The flaw allows unauthorized access to the router's management interface resulting in a loss of confidentiality.

2004-10-26 Unknow
2004-10-26 Unknow

Upgrade to firmware version CX82xxx_4.1.0.21 or higher, as it has been reported to fix this vulnerability. It is also possible to correct the flaw by implementing the following workaround(s): 1) Use the "Virtual Host" feature in the modem's browser interface to forward ports 23, 254, and 255 to a nonexistent host (such as ""). This still allows access from the firewall side of the modem, however. 2) Put the modem into "bridge mode" and do all your NAT, PPPoE, and security from your linux firewall.

