Release date:
Updated on:
Affected Systems:
Logitec LAN-W300N Co., LAN-W300N/RU2 firmware 2.17
Logitec LAN-W300N LAN-W300N/RS firmware 2.17
Logitec LAN-W300N LAN-W300N/R firmware 2.17
Description:
--------------------------------------------------------------------------------
Bugtraq id: 53685
Cve id: CVE-2012-1250
The Logitec LAN-W300N/R is a wireless LAN router.
Logitec LAN-W300N/R, LAN-W300N/RS, LAN-W300N/RU2 series 2.17 has no access restrictions on implementations, allowing attackers to log on to the product with administrator privileges, thus changing settings and obtaining PPPoE creden.
<* Source: Jin Sawada
Keisuke Okazaki
Naoto Katsumi
Link: http://jvn.jp/en/jp/JVN85934986/index.html
Http://jvndb.jvn.jp/en/contents/2012/JVNDB-2012-000051.html
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Logitec
-------
Logitec has released a Security Bulletin (JVNDB-2012-000051) and patches for this:
JVNDB-2012-000051: Logitec LAN-W300N/R series fails to restrict access permissions
Link: http://jvndb.jvn.jp/en/contents/2012/JVNDB-2012-000051.html