CVE-2017-16523
CRITICALMitraStar GPT-2541GNAC and DSL-100HN-T1 - Hardcoded Password
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-16523. PoCs published by j0lama.
AI-analyzed exploit summary This exploit leverages a misconfigured SSH service on MitraStar routers, allowing command execution via SSH with root privileges by bypassing the default shell. The vulnerability is due to improper SSH configuration, enabling direct shell access.
Description
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented.
Exploits (1)
This exploit leverages a misconfigured SSH service on MitraStar routers, allowing command execution via SSH with root privileges by bypassing the default shell. The vulnerability is due to improper SSH configuration, enabling direct shell access.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H