Skip to content

metac0rtex/CVE-2022-24693

 
 

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

2 Commits
 
 
 
 

Repository files navigation

CVE-2022-24693

Description

Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)

CVSS Score

(Somewhere between 9.5 and 10.0)

Vulnerability Type

Incorrect Access Control

Vendor of Product

BaiCells

Affected Product Code Base

NOVA436Q - QRTB 2.7.8 (Likely all builds before 2.9.x) NEUTRINO430 - QRTB 2.7.8 (Likely all builds before 2.9.x)

Affected Component

Usernames and Passwords are static in the firmware, encrypted using crypt(), and so are crackable.

Attack Type

Remote

Impact Code execution

True

Impact Denial of Service

True

Impact Escalation of Privileges

True

Impact Information Disclosure

True

Attack Vectors

Out of the box, the firmware has static usernames and passwords.

Reference

https://na.baicells.com/Service/Firmware https://img.baicells.com//Upload/20211230/FILE/BaiBS_QRTB_2.7.8.IMG.IMG https://img.baicells.com//Upload/20210909/FILE/98d2752f-6e83-49b1-9dab-d291e9023db6.pdf

Has vendor confirmed or acknowledged the vulnerability?

Yes, though not publicly.

Discoverer

Luke Jenkins

Timeline

(timeline goes here)

Details:

User "admin" password of "Baicells" stored using unix crypt() DES algorithm.

Undocumented & non-configurable user "anonymous" password of "pqmz325" stored using unix crypt() DES algorithm.

Undocumented, non-configurable (but seemingly unusable for ssh) user "root" password of "qpa;10@)" stored using unix crypt() DES algorithm. Vendor claims this is unique per device, but this hasn't been confirmed.

Notes

This is my first published CVE, so please excuse (or pull request) any errors.

Thanks to the folks at UETN for the assistance and backing on this one.

Also thank you to the staff of Baicells NA for working with me on correcting this issue.

About

No description, website, or topics provided.

Resources

License

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published