Skip to content

Latest commit

 

History

History
17 lines (13 loc) · 1.31 KB

auth_bypass.md

File metadata and controls

17 lines (13 loc) · 1.31 KB

CVE-2022-47700

Vendor: COMFAST (Shenzhen Sihai Zhonglian Network Technology Co., Ltd)

Firmware version: V2.3.0.1

Driver version: 4.1.0.0_CL15074

Vendor Fix: N/A

Impact: Unauthenticated Information Disclosure

Description: an aunauthenticated user has the ability to disclose the admin accounts credentials.


I'll preface this by saying that obviously you do need to be connected to the network to perform this attack. You can achieve this by plugging directly into the router. This is assuming you have physical access or have the owner of the device provide you with the PSK or connect you themselves. Then and only then can you interface with the device.

As seen below, since we don't actually need to be authenticate or have a valid session we have more-or-less access to all the router features. Because of this we're able to retrieve the routers configuration and view the admin users password and see the PSK in clear text.

image

image