|
Siemens Santis 50 contains a flaw that may allow remote privilege escalation. The issue is triggered when random traffic is sent to the router web administration port (280/tcp), which will crash the web server, and switch the telnet server into "recovery mode", allowing unauthenticated telnet logins. Once logged in, the user will have access to a number of administrative commands, including "irreversibly erasing FLASH contents", abuse of which can result in loss of availability for the Siemens Santis 50.
|