EuroTel ETL3100 versions v01c01 and v01x37 suffer from an unauthenticated configuration and log download vulnerability. This enables the attacker to disclose sensitive information and assist in authentication bypass, privilege escalation, and full system access.
The vulnerability results from the lack of authentication requirements when accessing endpoints that provide configuration files and device logs. An unauthorized attacker can remotely download these files over the network without any permissions and without user interaction. Data obtained in this way (e.g., credentials, keys, passwords) enables further attacks — including authentication bypass and privilege escalation leading to full system access.
An attacker can gain full access to sensitive device configuration data and logs, and then use them to bypass authentication, escalate privileges, and take full control of the device.
Apply patches available from the manufacturer in accordance with the references. Detailed recommendations are contained in the CISA ICS Advisory message: ICSA-23-353-05. Until the update is applied, it is recommended to restrict network access to the device only to trusted hosts and isolate the device behind a firewall.
EuroTel ETL3100 Firmware in versions v01c01 and v01x37
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:HEurotel Etl3100
HWEurotelall versionsEurotel Etl3100 Firmware
OSEurotel01c0101x37