Update: Full Disclosure - WD My Net N600, N750, N900, N900C - Plain Text Disclosure of Admin Credentials

2013-08-01 Thread krlovett
Vulnerable Systems: Western Digital My Net Series Wireless Routers: N600 Firmware 1.03.12 N600 Firmware 1.04.16 N750 Firmware 1.03.12 N750 Firmware 1.04.16 N900 Firmware 1.05.12 N900 Firmware 1.06.18 N900 Firmware 1.06.28 N900C Firmware 1.05.12 N900C Firmware 1.06.18 N900C Firmware 1.06.2

Re: Full Disclosure ASUS Wireless Routers Ten Models - Multiple Vulnerabilities on AiCloud enabled units

2013-07-17 Thread krlovett
Update: The new Firmware tests for the ASUS 66 and 56 series have shown that access to the root share and directory traversal are no longer possible. We'll conduct more testing on the N14 and 16 series when those are released in the next day or two. It is recommended that all users upgrade as s

Re: Full Disclosure ASUS Wireless Routers Ten Models - Multiple Vulnerabilities on AiCloud enabled units

2013-07-17 Thread krlovett
Update: The new Firmware tests for the ASUS 66 and 56 series have shown that access to the root share and directory traversal are no longer possible. We'll conduct more testing on the N14 and 16 series when those are released in the next day or two. It is recommended that all users upgrade as s

Re: OS-Command Injection via UPnP Interface in multiple D-Link devices

2013-07-08 Thread krlovett
I can concur these issues exist in several other models as well. In fact, on any UPnP enabled D-Link from 868L and down, merely selecting "Display Hidden Elements" inside the developer tool bar, will expose the entire administrative GUI. Additional models I found the same bug, though I'm so sur

Re: Linksys EA - 2700, 3500, 4200, 4500 w/ Lighttpd 1.4.28 Unauthenticated Remote Administration Access

2013-07-03 Thread krlovett
Just a quick update, that the newest firmware versions for E4200 and EA45000 are still being tested, but it is a safe bet to upgrade to Ver.2.1.39.145204, even though the bug hasn't been tested yet against this ver yet. http://support.linksys.com/en-eu/support/routers/EA4500/download