b_banner.stm (aka the login page) on the Deutsche Telekom Speedport W500 DSL router allows remote attackers to obtain the logon password by reading the pwd field in the HTML source.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/archive/1/489009/100/0/threaded | mailing list |
http://www.gnucitizen.org/projects/router-hacking-challenge/ | exploit |
http://www.securityfocus.com/bid/28382 | vdb entry |
http://secunia.com/advisories/29414 | third party advisory |
https://exchange.xforce.ibmcloud.com/vulnerabilities/41128 | vdb entry |