Last active
September 17, 2025 14:52
-
-
Save numanturle/c99d3306e9e4e17bb2164dde363406bc to your computer and use it in GitHub Desktop.
Vmg3312 B10b Firmware Vmg3312 B10b Firmware backdoor account
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| root@bitforbyte:~/xxx# binwalk 100AAPP7D0.bin | |
| DECIMAL HEXADECIMAL DESCRIPTION | |
| -------------------------------------------------------------------------------- | |
| 131072 0x20000 JFFS2 filesystem, big endian | |
| JFFS2 filesystem extract | |
| total 1492 | |
| 1049502 drwxr-xr-x 18 root root 4096 Oct 27 23:33 . | |
| 1049493 drwxr-xr-x 3 root root 4096 Oct 27 23:33 .. | |
| 1049503 drwxr-xr-x 2 root root 4096 Oct 27 23:33 bin | |
| 1049509 drwxr-xr-x 2 root root 4096 Oct 27 23:33 data | |
| 1049510 drwxr-xr-x 5 root root 4096 Oct 27 23:33 dev | |
| 1049512 drwxr-xr-x 14 root root 4096 Oct 27 23:33 etc | |
| 1049513 drwxr-xr-x 2 root root 4096 Oct 27 23:33 firmware | |
| 1049514 drwxr-xr-x 2 root root 4096 Oct 27 23:33 home | |
| 1049515 drwxr-xr-x 6 root root 4096 Oct 27 23:33 lib | |
| 1049516 lrwxrwxrwx 1 root root 11 Oct 27 23:33 linuxrc -> bin/busybox | |
| 1049517 drwxr-xr-x 2 root root 4096 Oct 27 23:33 log | |
| 1049518 drwxr-xr-x 2 root root 4096 Oct 27 23:33 mnt | |
| 1049519 drwxr-xr-x 5 root root 4096 Oct 27 23:33 opt | |
| 1049520 drwxr-xr-x 2 root root 4096 Oct 27 23:33 proc | |
| 1049521 drwxr-xr-x 2 root root 4096 Oct 27 23:33 sbin | |
| 1049522 drwxr-xr-x 2 root root 4096 Oct 27 23:33 sys | |
| 1049523 lrwxrwxrwx 1 root root 8 Oct 27 23:33 tmp -> /var/tmp | |
| 1049524 drwxr-xr-x 4 root root 4096 Oct 27 23:33 usr | |
| 1049525 drwxr-xr-x 3 root root 4096 Oct 27 23:33 var | |
| 1049526 -rw-r--r-- 1 root root 1450819 Oct 27 23:33 vmlinux.lz | |
| 1049527 drwxr-xr-x 4 root root 4096 Oct 27 23:33 webs | |
| open etc/default.cfg | |
| <User instance="2"> | |
| <Enable>TRUE</Enable> | |
| <Level>2</Level> | |
| <Username>root</Username> | |
| <Password>dFRuMytaQCFTcjBPKwA=</Password> | |
| </User> | |
| base64 decode for password <Password> ; tTn3+Z@!Sr0O+ | |
| root:tTn3+Z@!Sr0O+ |
hi @anildurgun,
there is no modem under the name “Vmg3312” belonging to the TP-Link.
Zyxel has this model. It is recommended to upgrade to the latest version shared by the supplier company. This product is really common in Turkey, but it is also an old model.
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
We recently got a similar question on our Techdergi site and shared an answer. I’d appreciate your thoughts does our response look correct to you?
Question link: https://www.techdergi.net/soru-cevap/tp-link-vmg3312-arka-kapi-varmis-dogru-mu-bir-sorun-olur-mu