The command deviceinfo show file is supposed to be used from reduced CLI to show files and directories. Because this command do not handle correctly special characters, is possible to insert a second command as a parameter in the "path" value. Using "\n /bin/bash" as a parameter value, we can generate a console with root access, as seen below:
> deviceinfo show file "\n /bin/bash"
app bosa data etc lib mini_httpdroot sbin tmp usr
bin bosabackup dev fwbuffer linuxrc proc sys userfs var
So it is possible to escalate privileges by spawning a full interoperable console with root privileges
Through this escalation we can change the content of /etc/passwd or (/var/passwd), create new users, or change any other system resource permanently.
The user support is provided printed on the back of the router. In some cases, this routers use default credentials.