Dasan Networks GPON ONT WiFi Router H64X Series System Config Download

Title: Dasan Networks GPON ONT WiFi Router H64X Series System Config Download
Advisory ID: ZSL-2017-5424
Type: Local/Remote
Impact: Security Bypass, Exposure of System Information, Exposure of Sensitive Information
Risk: (4/5)
Release Date: 12.07.2017
Summary
H64xx is comprised of one G-PON uplink port and four ports of Gigabit Ethernet downlink supporting 10/100/1000Base-T (RJ45). It helps service providers to extend their core optical network all the way to their subscribers, eliminating bandwidth bottlenecks in the last mile. H64xx is integrated device that provide the high quality Internet, telephony service (VoIP) and IPTV or OTT content for home or office. H64xx enable the subscribers to make a phone call whose quality is equal to PSTN at competitive price, and enjoy the high quality resolution live video and service such as VoD or High Speed Internet.
Description
The system backup configuration file 'running.CFG' and the wireless backup configuration file 'wifi.CFG' can be downloaded by an attacker from the root directory in certain circumstances. This will enable the attacker to disclose sensitive information and help her in authentication bypass, privilege escalation and/or full system access.
Vendor
Dasan Networks - http://www.dasannetworks.com
Affected Version
Models: H640GR-02
H640GV-03
H640GW-02
H640RW-02
H645G

Firmware:
3.02p2-1141
2.77p1-1125
2.77-1115
2.76-9999
2.76-1101
2.67-1070
2.45-1045
Tested On
Server: lighttpd/1.4.31
Server: DasanNetwork Solution
Vendor Status
[19.05.2017] Vulnerability discovered.
[30.05.2017] Vendor contacted.
[30.05.2017] Vendor replied asking more details.
[31.05.2017] Sent details to the vendor.
[01.06.2017] Vendor provides latest firmware version 3.03-1144-01.
[01.06.2017] Working with the vendor.
[05.07.2017] Vendor responds that the 3.03 version has some fixes like backup file password security. Vendor asks if it's possible to test on latest version.
[05.07.2017] Replied to the vendor that if they provide a sample, we can execute.
[05.07.2017] Vendor provides public IP access to test version 3.03p1-1145. Config download fixed with 7z password protection.
[05.07.2017] Informed the vendor about the other issues.
[05.07.2017] Vendor replied.
[13.07.2017] Asked vendor for status update.
[13.07.2017] Vendor will fix remaining issues in next FW release. No confirmed date for new release.
[13.07.2017] Coordinated public security advisory released.
PoC
dasan-h64_config.txt
Credits
Vulnerability discovered by Gjoko Krstic - <gjoko@zeroscience.mk>
References
[1] https://www.exploit-db.com/exploits/42323/
[2] https://cxsecurity.com/issue/WLB-2017070102
[3] https://packetstormsecurity.com/files/143364
[4] https://exchange.xforce.ibmcloud.com/vulnerabilities/129748
Changelog
[12.07.2017] - Initial release
[01.08.2017] - Added reference [1], [2] and [3]
[15.11.2017] - Added reference [4]
Contact
Zero Science Lab

Web: http://www.zeroscience.mk
e-mail: lab@zeroscience.mk