Cudy WR3000H V1.0 V2.4.5 is discovered to contain an Offline Password Guessing vulnerability. This vulnerability allows local attackers to execute Offline Password Guessing attack.
Affected Products
Product
Severity
Fixed Release Availability
AX3000 2.5G 網狀 Wi-Fi 6 路由器, WR3000H 1.0
Important
firmware update
Mitigation
Cudy has released firmware 2.5.30 which fixed this issue.
Detail
The router accepts administrator authentication over plaintext HTTP. A captured request therefore allows unrestricted offline validation of candidate passwords. The successful response creates the sysauth session cookie without the Secure attribute.
Acknowledgement
Muhamed Fakhri Sabour — Security Researcher, Computer & Information Engineering Student, Ninevah University, Iraq.