exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

TP-Link Archer C50 Insecure Connections

TP-Link Archer C50 Insecure Connections
Posted Apr 11, 2019
Authored by Harley A.W. Lorenzo

An initial analysis of the TP-Link Archer C50 router shows it accepts logins over HTTP, uses a telnet server, and implements SSH with low-bit DSA and RSA keys.

tags | advisory, web
SHA-256 | 53a13e884f6afc26588d4379a2f778d837337905887f64e1979b2754e287ed7e

TP-Link Archer C50 Insecure Connections

Change Mirror Download
================================================================================
Title: Security Analysis of the TP-Link Archer C50 Router
Version: Archer C50(US)_V2_160801 (latest firmware available)
Product Page: https://www.tp-link.com/us/home-networking/wifi-router/archer-c50/
Published: 2019-04-10 (UTC Time)
Published by: Harley A.W. Lorenzo <hl1998@protonmail.com>
<GPG Key: 0xF6EF23904645BA53>
================================================================================

================
Security Details
================

* The C50 router implements a completely unencrypted HTTP authentication
login handshake on its port 80 HTTP server for administrative tasks
* The C50 router implements a telnet server over Busybox Telnetd
* The C50 router implements an SSH service with on Dropbear 2012.55 with
low-bit DSA and RSA keys (1024 and 1040-bit respecitvely)

===================
Login Sniffing/MITM
===================

Because of C50 router login handshake is completely unencrypted (both over HTTP
and telnet) any attacker with access to the network data sent to the router
can easily acquire the username and password sent in the login.

For example, the following proof of concept regarding HTTP traffic:

1. Set up a valid sniffer and listen for the HTTP traffic sent to the server
2. Login to the server via its webserver
3. Watch for a GET request to its base index with a cookie with the format
Authorization=BASIC {[user]:[pass]}
* Where [user] is replaced with the username and [pass] is
replaced with the password entered
* Where everything in {} is encoded in base64

===
SSH
===

* The SSH server is possibly vulnerable to serveral CVEs regarding Dropbear
* DSA is an deprecated singing algorithm and is better replaced with ECDSA
* Both the DSA and RSA keys are well below the recommended size

================
Additional Notes
================

Beside the HTTP sniffing PoC, these are all preliminary findings, and this
research is an ongoing effort.


Login or Register to add favorites

File Archive:

March 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Mar 1st
    16 Files
  • 2
    Mar 2nd
    0 Files
  • 3
    Mar 3rd
    0 Files
  • 4
    Mar 4th
    32 Files
  • 5
    Mar 5th
    28 Files
  • 6
    Mar 6th
    42 Files
  • 7
    Mar 7th
    17 Files
  • 8
    Mar 8th
    13 Files
  • 9
    Mar 9th
    0 Files
  • 10
    Mar 10th
    0 Files
  • 11
    Mar 11th
    15 Files
  • 12
    Mar 12th
    19 Files
  • 13
    Mar 13th
    21 Files
  • 14
    Mar 14th
    38 Files
  • 15
    Mar 15th
    15 Files
  • 16
    Mar 16th
    0 Files
  • 17
    Mar 17th
    0 Files
  • 18
    Mar 18th
    10 Files
  • 19
    Mar 19th
    32 Files
  • 20
    Mar 20th
    46 Files
  • 21
    Mar 21st
    16 Files
  • 22
    Mar 22nd
    13 Files
  • 23
    Mar 23rd
    0 Files
  • 24
    Mar 24th
    0 Files
  • 25
    Mar 25th
    12 Files
  • 26
    Mar 26th
    31 Files
  • 27
    Mar 27th
    19 Files
  • 28
    Mar 28th
    42 Files
  • 29
    Mar 29th
    0 Files
  • 30
    Mar 30th
    0 Files
  • 31
    Mar 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close