Vulnerabilities > CVE-2004-1550 - Remote Authentication Bypass vulnerability in Motorola Wr850G 4.0.3Firmware

047910
CVSS 7.5 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL
network
low complexity
motorola
metasploit

Summary

Motorola Wireless Router WR850G running firmware 4.03 allows remote attackers to bypass authentication, log on as an administrator, and obtain sensitive information by repeatedly making an HTTP request for ver.asp until an administrator logs on.

Vulnerable Configurations

Part Description Count
Hardware
Motorola
1

Metasploit

descriptionLogin credentials to the Motorola WR850G router with firmware v4.03 can be obtained via a simple GET request if issued while the administrator is logged in. A lot more information is available through this request, but you can get it all and more after logging in.
idMSF:AUXILIARY/ADMIN/MOTOROLA/WR850G_CRED
last seen2020-06-01
modified2018-09-15
published2008-10-06
references
reporterRapid7
sourcehttps://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/admin/motorola/wr850g_cred.rb
titleMotorola WR850G v4.03 Credentials