Executive brief
Critical network infrastructure such as routers and firewalls are configured with easily guessable or default passwords. This allows unauthorized individuals to gain administrative access to the network's backbone. An attacker could intercept sensitive data, redirect traffic, or shut down network services entirely, leading to significant operational disruption and data breaches.
Technical details
This vulnerability involves the use of weak, default, or easily guessable credentials on network infrastructure devices such as routers and firewalls. It is categorized as a failure to implement strong authentication or a failure to change default configurations. An attacker with network reachability to the device's management interface (e.g., Telnet, SSH, or Web GUI) can perform a brute-force or dictionary attack to gain access. Successful exploitation grants the attacker the privileges associated with the compromised account, typically allowing for full device reconfiguration, traffic sniffing, or denial-of-service. Remediation requires enforcing strong password policies and ensuring all default vendor credentials are changed upon deployment.
Affected products
- Generic Network Device Firmware
Timeline
- 1998-04-01: disclosed