Zyxel/Eir D1000 DSL Modem NewNTPServer Command Injection Over TR-064
Posted by deepcore on January 5, 2017 – 12:08 pm
Broadband DSL modems manufactured by Zyxel and distributed by some European ISPs are vulnerable to a command injection vulnerability when setting the ‘NewNTPServer’ value using the TR-64 SOAP-based configuration protocol. In the tested case, no authentication is required to set this value on affected DSL modems. This exploit was originally tested on firmware versions up to 2.00(AADU.5)_20150909.
Post a reply
You must be logged in to post a comment.