Router UI accessible via public IP address

Back in 2010 there was a Blackhat presentation about DNS rebinding

http://blackhat.com/html/bh-us-10/bh-us-10-archives.html#Heffner

I tested a Surf Soho running firmware 7.0.1 build 2621.
From computer on the LAN side, I enter this in my web browser

https://publicIPaddress:9999

and the browser fails to load the page. All well and good. LAN side admin access is limited to HTTPS.

But, 9999 is not the port I use for admin access! When I change this to use the correct port, I get a Not Found error from this URL

https://publicIPaddress:correctport/cgi-bin/MANGA/index.cgi

This seems bad. It shows the router processed something. This is a very different result compared to using the wrong port number.

Is this a bug?

I tested with a MacBook + Safari from the LAN side, and Windows + Chrome (incognito mode) from the WAN side, both showing me the same results that it cannot be accessed.

My device web admin access setting is HTTPS (8443) and LAN only.

(A) MacBook + Safari from LAN side:

  1. https://WAN-IPaddress:9000 - wait 2 minutes then “Safari Can’t Open the Page” error appears

  2. https://WAN-IPaddress:8443 - wait 2 minutes then “Safari Can’t Open the Page” error appears

  3. https://WAN-IPaddress:8443/cgi-bin/MANGA/index.cgi - wait 2 minutes then “Safari Can’t Open the Page” error appears

  4. https://LAN-IP:8443 - able to gain access to Web Admin

(B) Windows + Chrome (incognito mode) from WAN side:

  1. https://WAN-IPaddress:9000 - wait 1 minute then “The site can’t be reached” error appears

  2. https://WAN-IPaddress:8443 - wait 1 minute then “The site can’t be reached” error appears

  3. https://WAN-IPaddress:8443/cgi-bin/MANGA/index.cgi - wait 1 minute then “The site can’t be reached” error appears

The unit is SoHo HW2 - Firmware 7.0.1 build 2621. Also tested with SoHo MK3 with 7.0.1GA with same results.

Do you mind to share more details how to replicate your issue, or you can open a support ticket for better follow up?

1 Like

Let me try some more OSs and browsers and get back to you…
My router is Surf SOHO HW2 Firmware: 7.0.1 build 2621 - same as yours.