cR0w on Nostr: > The web server binary /bin/httpd> contains an undocumented backdoor authentication ...
https://kb.cert.org/vuls/id/213560> The web server binary /bin/httpd> contains an undocumented backdoor authentication mechanism in the login()> function. Initially, the function follows a normal authentication path using MD5-based password verification. However, if authentication fails, the function invokes GetValue("sys.rzadmin.password")> to retrieve an alternate password value from the device configuration. It then performs a direct strcmp()> comparison in plaintext between the user-supplied password and the configuration-stored value. A successful match grants role=2> admin-level access and creates a valid session.
> The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface.
Published at
2026-07-06 21:38:51 CESTEvent JSON
{
"id": "16612a34e1b3509858690829cbcfaa2316c88b29b75654b641d92a18eb23dd08",
"pubkey": "86b397086a130510861dd58f255fadeee1c47815185fa3bb628a06b4d6af31ac",
"created_at": 1783366731,
"kind": 1,
"tags": [
[
"imeta",
"url https://media.infosec.exchange/infosec.exchange/media_attachments/files/116/874/721/196/268/865/original/460f7d05d55bce28.png",
"m image/png"
],
[
"proxy",
"https://infosec.exchange/@cR0w/116874722118472440",
"web"
],
[
"proxy",
"https://infosec.exchange/users/cR0w/statuses/116874722118472440",
"activitypub"
],
[
"L",
"pink.momostr"
],
[
"l",
"pink.momostr.activitypub:https://infosec.exchange/users/cR0w/statuses/116874722118472440",
"pink.momostr"
],
[
"-"
]
],
"content": "https://kb.cert.org/vuls/id/213560\n\n\u003e The web server binary /bin/httpd\u003e contains an undocumented backdoor authentication mechanism in the login()\u003e function. Initially, the function follows a normal authentication path using MD5-based password verification. However, if authentication fails, the function invokes GetValue(\"sys.rzadmin.password\")\u003e to retrieve an alternate password value from the device configuration. It then performs a direct strcmp()\u003e comparison in plaintext between the user-supplied password and the configuration-stored value. A successful match grants role=2\u003e admin-level access and creates a valid session.\n\n\u003e The associated username is not validated, so any provided username will succeed when paired with the backdoor password. This backdoor authentication mechanism is not documented or visible through any administrative interface.\nhttps://media.infosec.exchange/infosec.exchange/media_attachments/files/116/874/721/196/268/865/original/460f7d05d55bce28.png\n",
"sig": "02fcd5a6b5354c8cd081e1111074190c020255d29ebf7e6eb9f85ea4f3c9b7efb4ec1696927f2103a8899aec1414414fa22400472aac5dea972075a2ebaf17fe"
}