Skip to content

Latest commit

 

History

History
29 lines (15 loc) · 930 Bytes

2.md

File metadata and controls

29 lines (15 loc) · 930 Bytes

D-LINK Go-RT-AC750 has a hardcoded password

Product information

Vendor of the product: https://www.dlink.com/

Product version: D-Link Go-RT-AC750 GORTAC750_A1_FW_v101b03

vulnablitity overview

D-LINK Go-RT-AC750 GORTAC750_A1_FW_v101b03 has a hardcoded password for the Alphanetworks account, which allows remote attackers to obtain root access via a telnet session.

Analyse

telnetd - l/usr/sbin/login - u Alphanetworks: $image_ Sign - i br0& can be found in etc/init0.d/S80telnetd.sh

img1

Then in /etc/config/image_sign

img2

These two places store the username and password of telnet

img3

Successfully logged in

CVE-2024-22853