Document Title: =============== Vodafone EasyBox A600 WLan Router - Web Vulnerability Release Date: ============= 2011-09-15 Vulnerability Laboratory ID (VL-ID): ==================================== 100 Product & Service Introduction: =============================== Die EasyBox A 601 eignet sich zum Anschluss von analogen Endgeräten. Verbinden Sie bis zu vier PCs per Kabel mit der EasyBox und weitere kabellos per WLAN. Zu Ihrer Sicherheit ist das WLAN bereits ab Werk verschl¸sselt. * DSL-Router zum Anschluss mehrerer PCs * integriertes DSL-Modem * Telefonanlage für analoge Endger‰te * WLAN ab Werk verschl¸sselt * integrierte Firewall (Copy of the Vendor Homepage: http://www.vodafone.com) Abstract Advisory Information: ============================== Vulnerability Lab Team discovered a persistent Web Vulnerability in Vodafones EasyBox A600 W-LAN Router Firmware. Vulnerability Disclosure Timeline: ================================== 2011-09-16: Public or Non-Public Disclosure Discovery Status: ================= Published Affected Product(s): ==================== Exploitation Technique: ======================= Remote Severity Level: =============== Medium Technical Details & Description: ================================ An Input Validation Vulnerability is detected on the dns module input of the vodafone easybox A600. The bug allows an attacker to inject own malicious persistent script code to manipulate the router interface & firmware functions. Vulnerable Module(s): [+] DNS/DDNS Input/Output Proof of Concept (PoC): ======================= The vulnerability can be exploited by attackers. For demonstration or reproducement ... Reference: [Scriptcode/Tags]@[anymail.server] PoC: >"