Belkin F5D7230-4 router security bypass
| belkin-f5d72304-security-bypass (41120) |
Description:
The Belkin F5D7230-4 router could allow a remote attacker to bypass security restrictions. The authentication state is maintained by the user's source IP address. A remote attacker could exploit this vulnerability to establish a session to the device using previously authenticated credentials via the source IP of the victim.
Platforms Affected:
- Belkin, Belkin F5D7230-4 9.01.10
Remedy:
No remedy available as of September 6, 2008.
Consequences:
Bypass Security
References:
- Belkin Support Web site, Belkin : Support : Wireless G Router : F5D7230-4 at http://www.belkin.com/support/product/?lid=en&pid=F5D7230-4&scid=221.
- BugTraq Mailing List, Sat Mar 01 2008 - 16:08:29 CST, The Router Hacking Challenge is Over! at http://archives.neohapsis.com/archives/bugtraq/2008-03/0006.html.
- GNUCITIZEN Blog, February 3rd, 2008, Router Hacking Challenge at http://www.gnucitizen.org/projects/router-hacking-challenge/.
- BID-28317: Belkin F5D7230-4 Wireless G Router IP-Based Authentication State Authentication Bypass Vulnerability
- CVE-2008-1242: The control panel on the Belkin F5D7230-4 router with firmware 9.01.10 maintains authentication state by IP address, which allows remote attackers to bypass authentication by establishing a session from a source IP address of a previously authenticated user, a different vulnerability than CVE-2005-3802.
- SA29345: Belkin Wireless G Router Security Bypass and Denial of Service
Reported:
Mar 10, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
