CyberRota Analysis
AI-GeneratedThe web server binary contains a critical backdoor authentication mechanism that allows unauthorized access by bypassing normal authentication processes. When standard login fails, the system retrieves a hardcoded backdoor password from the device configuration, granting admin-level access to any username provided. Organizations using this affected web server should prioritize immediate remediation to prevent potential exploitation and unauthorized control over their systems.
Original NVD Description
The web server binary /bin/httpd contains a hidden backdoor authentication mechanism in the login() function at 004c88b8. - The function contains a normal authentication path using MD5/hash-based password verification (prod_encode64/PasswordToMd5/check_rand_key). - After normal authentication fails, it calls GetValue("sys.rzadmin.password") to read a backdoor password from the device configuration. - It performs a direct strcmp() comparison (plaintext, not hashed) between the config value and the user-supplied password. A successful match grants role=2 (admin-level access) and creates a valid session. The rzadmin username is never checked — any username works with the backdoor