Title: 3Com OfficeConnect Wireless Cable/DSL Router Unauthorized Remote Administration Vulnerability
Severity: MODERATE
Description:
The 3Com OfficeConnect Wireless Cable/DSL Router is a networking device identified by product number 3CRWER100-75.
The device is prone to a vulnerability that can result in unauthorized remote administration.
This issue occurs when the device is configured with remote management disabled. If a virtual server is assigned to port 80 and the corresponding entry under the management interface's firewall tab is not selected, remote computers will be able to access the remote management interface.
NOTE: If the firewall entry is selected and remote computers try to connect to the device's management interface, the device will return a webpage hosted on the virtual server (or a TCP error if a webpage does not exist).
This issue can result in a false sense of security because it exposes the device to remote access even though administrative settings state otherwise. Attackers can exploit this issue to potentially gain administrative access to the device.
Affected Products:
- 3Com OfficeConnect Wireless 54Mbps 11g Cable/DSL Router 3CRWER100-75
References:
Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.