Jump to content

Back door potentially discovered in firmware of FTTH C Data devices

BlkAbysss

The original report discusses how to extract admin credentials, allowing an attacker to eventually run root level commands. To get the credentials you need access to the WAN or  FTTH LAN interface. 
 

I have minimal understanding in networking, and am curious about the feasibility of the attack. Does this attack rely on direct access to the devices, or can these WAN ports be found through the ISP’s network?


Summary Article:

https://www.zdnet.com/google-amp/article/backdoor-accounts-discovered-in-29-ftth-devices-from-chinese-vendor-c-data/

 

Original GitHub report:

https://pierrekim.github.io/blog/2020-07-07-cdata-olt-0day-vulnerabilities.html

Link to comment
Share on other sites

Link to post
Share on other sites

If the WAN interface of the device holds the Public IP of the private network(s) behind it then yes this could be exploited from anywhere in the world where you can reach that Public IP. You don't require physical access if that is the case unless it's some sort of physical MITM attack.

Link to comment
Share on other sites

Link to post
Share on other sites

Unlikely that the OLT's have public IP's. Typically management of these devices is done with DHCP on a private network and TR-069 for the ISP that has deployed them to manage them. 

Spoiler

Desktop: Ryzen9 5950X | ASUS ROG Crosshair VIII Hero (Wifi) | EVGA RTX 3080Ti FTW3 | 32GB (2x16GB) Corsair Dominator Platinum RGB Pro 3600Mhz | EKWB EK-AIO 360D-RGB | EKWB EK-Vardar RGB Fans | 1TB Samsung 980 Pro, 4TB Samsung 980 Pro | Corsair 5000D Airflow | Corsair HX850 Platinum PSU | Asus ROG 42" OLED PG42UQ + LG 32" 32GK850G Monitor | Roccat Vulcan TKL Pro Keyboard | Logitech G Pro X Superlight  | MicroLab Solo 7C Speakers | Audio-Technica ATH-M50xBT2 LE Headphones | TC-Helicon GoXLR | Audio-Technica AT2035 | LTT Desk Mat | XBOX-X Controller | Windows 11 Pro

 

Spoiler

Server: Fractal Design Define R6 | Ryzen 3950x | ASRock X570 Taichi | EVGA GTX1070 FTW | 64GB (4x16GB) Corsair Vengeance LPX 3000Mhz | Corsair RM850v2 PSU | Fractal S36 Triple AIO | 12 x 8TB HGST Ultrastar He10 (WD Whitelabel) | 500GB Aorus Gen4 NVMe | 2 x 2TB Samsung 970 Evo Plus NVMe | LSI 9211-8i HBA

 

Link to comment
Share on other sites

Link to post
Share on other sites

Thanks for the explanations Jarsky and Windows7ge! 

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×