Credentials Stored in Cleartext Unencrypted Credentials (CVE‐2024‐33375) - Redfox-Security/Security-Advisory-Multiple-Vulnerabilities-in-Netgear-WNR614-Router GitHub Wiki
Description:
LB-LINK BL-W1210M v2.0 was discovered to store user credentials in plaintext within the router's firmware.
Impact:
The LB-LINK BL-W1210M router’s vulnerability involves storing credentials in plaintext, which may lead to unauthorized access and data risks. Urgent remediation is recommended.
Mitigation:
- Ensure encryption of all sensitive data, including credentials.
- Regularly audit and monitor access logs for unauthorized attempts.
POC:
LB-LINK routers’ storage of USER1 and USER2 credentials in plaintext poses a significant security threat. Immediate measures are required to prevent unauthorized access and ensure data protection.
Figure: Credentials stored in Cleartext