Dbl Trouble: Fix Falls Short for Backdoor in China-Made Devices
ID: 2293a57b-a195-5721-a22e-98b30dfcefc1
STIX ID: report--2293a57b-a195-5721-a22e-98b30dfcefc1
Feed Name: Security Ledger
Threat Score
Trustwave researchers discovered a hidden administrative Telnet backdoor account (username 'dbladm') in DblTek GoIP GSM gateway firmware that uses a weak, reversible challenge–response algorithm to produce an MD5-based login response; the flaw grants root-level access and affects multiple GoIP models. DblTek issued a patch, but the updated challenge–response implementation is still reversible, so affected devices may remain vulnerable and at risk of complete compromise.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
