Search

RailTel Fixes Vulnerabilities Impacting Official Site, Email System

Security researcher Sunny Nehra discovered various flaws impacting the RailTel site in early May.

Advertisement
Highlights
  • RailTel was informed about the issues last month
  • The organisation pulled its vulnerable password reset system
  • RailTel claimed that there had been no incident of data breach
RailTel Fixes Vulnerabilities Impacting Official Site, Email System

RailTel site was allegedly impacted with flaws that could have allowed hackers to gain root-level access

RailTel, the public sector enterprise that operates under the railway ministry and is known for providing Internet access at train stations, has fixed a list of serious vulnerabilities impacting its website. One of the issues could have allowed a hacker to reset a password of its email account holders, according to a security researcher. The RailTel site was also using an outdated version of the content management system Joomla that is impacted by a list of vulnerabilities, including the ones that can be exploited to let attackers gain root-level access or operate the site as an administrator.

Security researcher Sunny Nehra discovered various flaws impacting the RailTel site in early May. He informed Gadgets 360 that one of the issues could have allowed hackers to gain access to the email accounts of RailTel employees by resetting their passwords.

The researcher said that a bad actor could hack the email accounts since the organisation was not using a no-rate limit for the one-time password (OTP) mechanism available on its email password reset page. The limit is meant to restrict attackers from using various password combinations to eventually find the correct one.

In addition to the absence of the no-rate limit, the email system could allegedly be attacked using the response manipulation technique that attackers could leverage to bypass authentication.

"RailTel's mailing system was made in a very insecure way," Nehra told Gadgets 360. "Currently, it has turned the password reset page down."

The RailTel site was also using the Joomla version 3.4.2 that was released back in 2015. That particular release has been impacted by several known vulnerabilities.

Nehra said the site was impacted by a vulnerability that is tracked as CVE-2015-8562 and was exploited by some attackers in December 2015.

"The flaw leads to root access or complete hacking of the vulnerable server," he said, adding that other critical flaws of the outdated Joomla version also impacted the site.

To explain the flaws, Nehra shared three proof-of-concept (PoC) videos with Gadgets 360.

Shortly after spotting the issues, the researcher disclosed the vulnerabilities to RailTel and informed India's Computer Emergency Response Team (CERT-In) and National Critical Information Infrastructure Protection Centre (NCIIPC) on May 6. The CERT-In and NCIIPC last week confirmed to the researcher that the issues were patched by the enterprise.

RailTel also separately confirmed the fixes to Gadgets 360.

"RailTel's website runs behind a Web application firewall and is loaded with host-based antivirus and hence cyber attackers cannot exploit vulnerabilities, if any, and cannot upload shells to our website," the organisation said in a prepared statement emailed to Gadgets 360. "We would like to stress upon the fact that there has been NO INCIDENT of any data breach reported."

It also confirmed that its site was currently running on the latest stable release of Joomla platform.

"Also, currently we are not facing any issue related to the email account (railtelindia.com domain) compromise," it said.

RailTel runs a service called RailWire to offer free Wi-Fi access at railway stations in the country. It partnered with Google in 2016 to kick off a public Wi-Fi initiative called Google Station. The partnership, though, ended in May 2020. RailTel has, however, continued to provide free Wi-Fi service at hundreds of railway stations.

In 2017, the RailWire service was named as the worst affected service provider by the WannaCry ransomware by antivirus company eScan.

Aside from providing Internet access, RailTel in the recent past introduced technologies including an artificial intelligence (AI) based attendance system for government schools in Assam.


What is the best value flagship smartphone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

 
Show Full Article
Please wait...
Advertisement

Related Stories

Popular Mobile Brands
  1. HMD, Lava to Launch Direct-to-Mobile Phones in India With These Features
  2. Oppo Reno 14 Cameras, Buttons Revealed in Leaked Images
  3. OnePlus 13s Confirmed to Debut in India With This Chipset
  4. CMF Phone 2 Pro With Dimensity 7300 Pro SoC Launched in India: See Price
  5. Good Bad Ugly OTT Release Date: When and Where to Watch it Online?
  6. Realme GT 7 Will Launch in India Soon With 6-Hour 120 FPS BGMI Support
  7. iQOO Neo 10 Pro+ Specifications Tipped Ahead of Launch in China
  8. CMF Buds 2a, Buds 2 and Buds 2 Plus With ANC Debut in India: See Price
  9. Microsoft's Contentious Recall Feature is Rolling Out to Copilot+ PCs
  10. Asus ROG Strix Laptops With RTX 5000 Series GPU to Launch in India on May 2
  1. Huawei Watch 5, Watch Fit 4 Series Design, Pricing and Specifications Leaked via Retail Website
  2. HMD, Lava to Launch Direct-to-Mobile Phones in Partnership With Tejas Networks, FreeStream
  3. Bitget, Avalanche Announce Partnership to Boost Web3 Adoption in India
  4. CMF Phone 2 Pro With MediaTek Dimensity 7300 Pro SoC, Triple Rear Cameras Launched in India: Price, Specifications
  5. CMF Buds 2a, Buds 2 and Buds 2 Plus With Up to 14 Hours Battery Life Launched in India: Price, Features
  6. Supreme Court Seeks Response From Government on Sexually Explicit Content on Social Media, OTT Platforms
  7. Only Google Can Run Chrome, Company’s Browser Chief Tells Judge
  8. OpenAI Updates GPT-4o to Boost Intelligence and Personality, Faces Unexpected Side Effects
  9. South Asian Crypto Investors are Cautious, Demand Advanced Crypto Awareness, Survey Shows
  10. Clair Obscur: Expedition 33 Sells 1 Million Copies in 3 Days, Becomes Highest Rated Game of 2025
Gadgets 360 is available in
Download Our Apps
App Store App Store
Available in Hindi
App Store
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.
Trending Products »
Latest Tech News »