CERT-In Vulnerability Note
CIVN-2024-0158
Multiple Vulnerabilities in Digisol Router
Original Issue Date:May 10, 2024
Severity Rating: MEDIUM
Software Affected
- Digisol Router DG-GR1321: Hardware version 3.7L; Firmware version : v3.2.02
Overview
Multiple vulnerabilities have been reported in Digisol Router, which could allow a local attacker to perform security bypass or obtain sensitive information on the targeted system.
Description
1. Password Policy Bypass Vulnerability
(
CVE-2024-2257
)
This vulnerability exists in Digisol Router due to improper implementation of password policies. An attacker with physical access could exploit this by creating password that do not adhere to the defined security standards/policy on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to expose the router to potential security threats.
2. Incorrect Access Control Vulnerability
(
CVE-2024-4231
)
This vulnerability exists in Digisol Router due to presence of root terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by identifying UART pins and accessing the root shell on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to access the sensitive information on the targeted system.
3. Password Storage in Plaintext Vulnerability
(
CVE-2024-4232
)
This vulnerability exists in Digisol Router due to lack of encryption or hashing in storing of passwords within the routers firmware/ database. An attacker with physical access could exploit this by extracting the firmware and reverse engineer the binary data to access the plaintext passwords on the vulnerable system. Successful exploitation of this vulnerability could allow the attacker to gain unauthorized access to the targeted system.
Credit
These vulnerabilities are discovered by Shravan Singh, Ganesh Bakare and Karan Patel from Redfox Cyber Security Inc, Toronto, Canada.
Solution
Upgrade Digisol Router firmware to version v3.1.02-240311
https://www.digisol.com/firmware/
Vendor Information
Digisol Systems Limited
https://www.digisol.com/firmware/
References
Digisol Systems Limited
https://www.digisol.com/firmware/
CVE Name
CVE-2024-2257
CVE-2024-4231
CVE-2024-4232
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-22902657
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|