-
Notifications
You must be signed in to change notification settings - Fork 11
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security Analysis of Nokia G-120W-F #99
Comments
Could not access After login with AdminGPON, the user
Quagga daemons are each configurable via a network accessible CLI (called a 'vty'). The CLI follows a style similar to that of other routing software. |
Hello, how are you. I have one of the same model. you managed to access the shell |
@espetoet, If you are talking about 'user>shell', then I am still not able to access it. I was working on it yesterday but could not find anything. Neither a way to upgrade the router's firmware. If you have found any resources. Kindly, please do share. Thank you. |
Hello again. by chance you have the modem firmware. factory firmware |
Hello @codeanit , you can access the full shell with Telnet or SSH. Export the config file of the router and modify it's content and set LimitAccount_ONTUSER to false. Upload the modified config file back to the router and use the credentials ONTUSER:SUGAR2A041 to login into SSH or Telnet with full root permission. Follow this guide to decode the config file https://0x41.cf/reversing/2019/10/08/unlocking-nokia-g240wa.html Don't forget to read the comments from here : https://gist.github.com/thedroidgeek/80c379aa43b71015d71da130f85a435a Info about the credentials : https://www.tenable.com/security/research/tra-2019-09 |
After login with AdminGPON, the user user does not have previledges to update users. |
where to buy Onu Nokia Model G 120w F online |
The Password2 prompt after Tested on: |
Question: What to do after gaining root access ?? |
You can execute |
just discovered this issue.. |
Hi bro same device I have with same configuration , and backup and restore option not showing , Help me to solve my issue |
@amitgorai What's your Hardware Version and Boot version? The current CPEs used by Wlink have been updated with a new system. Every CPE now has a uniquely generated username and pass. And those command injection and ONTUSER backdoor account has already been removed on the latest BOOT version. |
Device Name: G-2425G-A Vendor: Nokia Hardware Version: 3FE48299DDAA Boot Version: U-Boot Dec-31-2016--12:00:00 Software Version: 3FE49362IJHK29 Chipset: MTK7528 |
Actually I was not using this router from last one year ,, I tried to use it on my existing wifi connection yesterday then I got to know ... It's fully locked... |
Hi @833M0L3 where I can use this password2 ?? |
@amitgorai what are you trying to achieve? If you want the admin access then try going into http://192.168.1.254/su.html and use
This should work if you haven't used your router for a long time since the change started happening recently. That is ofcourse if you are a wlink user. I have no idea about others. |
Hi @833M0L3 |
@amitgorai If you meant the telnet access , you can do that from windows terminal or using PUTTy. On the terminal enter telnet 192.168.1.254 . But since you have connected your router to the ISP , I am sure a lot of config has been changed and I am sure telnet/ssh are disabled by default. But give it a try. If you don't know how telnet and ssh works , try googling it. |
Did you progress |
@Albonycal |
What is happening here can someone make me understand |
The text was updated successfully, but these errors were encountered: