The flaw is in the web interface login flow associated with the uhttpd modules. The web interface encrypts the administrator password client-side with RSA-1024 before sending it to the router. An adjacent attacker able to intercept the traffic could collect the encrypted login data and attempt a brute-force or factorization attack against the 1024-bit RSA key to recover the plaintext password.
The high-level attack flow described by the record is:
- An administrator enters a password in the web interface.
- The client encrypts the password with RSA-1024 and sends the resulting data to the router.
- An adjacent attacker intercepts the traffic and attempts to recover the password from the weak RSA key.
- The recovered password may then be used for unauthorized access and compromise of the device configuration.
The record does not disclose how the key is generated, stored, or reused, what RSA padding is used, or whether each device has a unique key. Practical exploitability therefore depends on implementation details that have not been published and on the attacker's ability to intercept the relevant login traffic.