The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 allows a remote, unauthenticated attacker to enable telnetd on the router via a crafted HTTP request.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
The web application does not adequately enforce appropriate authorization on all restricted URLs, scripts, or files.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2019-09 | third party advisory exploit |