Credentials Stored in Cleartext Unencrypted Credentials (CVE‐2024‐33375) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki

Description:

LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.

Impact:

The LB-LINK BL-W1210M router’s vulnerability involves storing credentials in plaintext, which may lead to unauthorized access and data risks. Urgent remediation is recommended.

Mitigation:

  • Ensure encryption of all sensitive data, including credentials.
  • Regularly audit and monitor access logs for unauthorized attempts.

POC:

LB-LINK routers’ storage of USER1 and USER2 credentials in plaintext poses a significant security threat. Immediate measures are required to prevent unauthorized access and ensure data protection.

image Figure: Credentials stored in Cleartext