Results 1 to 9 of 9

Thread: @Thecus: N5200/2.00.04 vulnerabilities

  1. #1
    Registered User
    Join Date
    Jul 2007
    Posts
    3
    Thanks
    0
    Thanked
    0 times in 0 posts

    @Thecus: N5200/2.00.04 vulnerabilities

    @Thecus,

    please check tSupport for the following issues (partly CRITICAL):

    AGK-30478-710
    BTW-14968-778
    CDH-48427-714
    KWX-84921-681
    KOX-86555-282

    Two of them got a status of "bounced" which seems to be caused by the notofication mail not being delivered. If you (or your R&D guys) do not find one of these tickets please get back to me (take the email address from one of the tickets visible)

    Best regards,
    Falk John

  2. #2
    Thecus Staff Thecus - Yvon's Avatar
    Join Date
    Apr 2007
    Posts
    937
    Thanks
    0
    Thanked
    8 times in 8 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    Dear Sir,

    Thanks for post about these tickets, in fact we have some meeting about your issue for several times, thus we would reply to you directly.

    Yvon.

  3. #3
    Registered+
    Join Date
    Jul 2007
    Posts
    52
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    Yvon,

    there are 4 more tickets (numbers below).

    JSW-66307-431 (CRITICAL)
    EKX-11950-455
    CDI-96011-760
    EKL-94221-327

    Best regards,
    Falk

  4. #4
    Senior Member
    Join Date
    Jun 2007
    Location
    Austra
    Posts
    453
    Thanks
    0
    Thanked
    14 times in 14 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    Hi Falk,
    any reason why You don't share with us the problems?
    br
    Peter

  5. #5
    Registered+
    Join Date
    Nov 2007
    Posts
    19
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    yeah,
    if these vulnerabilities are there, dont owners deserve to know before their system's are victim?

    Knowing about something wrong with a product and not advising users is the best way to end up with lawyers on your back and really bad press.

  6. #6
    Registered+
    Join Date
    Jul 2007
    Posts
    52
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    To avoid answereing everyone by PM ...

    if I would post details on vulnerabilities no one except an owner of such a box will probably find your box WILL become a victim before Thecus is able to provide fixes. The last fixes took 4 months.

    What I can tell is that the WebUI is vulnerable to shell code injection - most of the issues require successful authentication so the risk is there but can be controlled.

    Best regards and Merry Christmas,
    Falk

  7. #7
    Senior Member
    Join Date
    Jun 2007
    Location
    Austra
    Posts
    453
    Thanks
    0
    Thanked
    14 times in 14 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    OK - I understand that security vulnerables are not posted public
    br
    Peter

  8. #8
    Registered+
    Join Date
    Nov 2007
    Posts
    19
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    I think what we need to know is:

    Do we need to disable access to the thecus units via the internet?
    (And whether it's just the N5200's that are affected)

    Obviously if all the issues require successful authentication before anything can be done, that is less of an issue.

  9. #9
    Registered+
    Join Date
    Jul 2007
    Posts
    52
    Thanks
    0
    Thanked
    0 times in 0 posts

    Re: @Thecus: N5200/2.00.04 vulnerabilities

    Some of the vulnerabilities do not require to be authenticated, some do.

    I would suggest not to open the WebUI to untrusted networks as long as no pre-authentication (Firewall, Proxy, ...) is performed - so, in most cases disable access to the WebUI from outside your LAN.

    Since I do not own other boxes then N5200/Pro I can not tell for sure if these vulnerabilities exist on others as well but I suppose that at least 1U4500 and N4100 may be affected. I will try to check these FWs today and will come back with the results.

    /Falk

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 0
    Last Post: 20-12-2007, 11:37 AM
  2. Replies: 1
    Last Post: 22-12-2005, 04:30 PM
  3. Router Vulnerabilities
    By Matt1eD in forum Networking and Broadband
    Replies: 1
    Last Post: 04-06-2005, 02:45 PM
  4. More people (read: morons) taking advantage of IE vulnerabilities
    By Paul Adams in forum General Discussion
    Replies: 13
    Last Post: 30-06-2004, 09:53 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •