RailTel Fixes Vulnerabilities Impacting Official Site, Email System

Security researcher Sunny Nehra discovered various flaws impacting the RailTel site in early May.

Advertisement
By Jagmeet Singh | Updated: 8 June 2022 16:04 IST
Highlights
  • RailTel was informed about the issues last month
  • The organisation pulled its vulnerable password reset system
  • RailTel claimed that there had been no incident of data breach

RailTel site was allegedly impacted with flaws that could have allowed hackers to gain root-level access

RailTel, the public sector enterprise that operates under the railway ministry and is known for providing Internet access at train stations, has fixed a list of serious vulnerabilities impacting its website. One of the issues could have allowed a hacker to reset a password of its email account holders, according to a security researcher. The RailTel site was also using an outdated version of the content management system Joomla that is impacted by a list of vulnerabilities, including the ones that can be exploited to let attackers gain root-level access or operate the site as an administrator.

Security researcher Sunny Nehra discovered various flaws impacting the RailTel site in early May. He informed Gadgets 360 that one of the issues could have allowed hackers to gain access to the email accounts of RailTel employees by resetting their passwords.

The researcher said that a bad actor could hack the email accounts since the organisation was not using a no-rate limit for the one-time password (OTP) mechanism available on its email password reset page. The limit is meant to restrict attackers from using various password combinations to eventually find the correct one.

Advertisement

In addition to the absence of the no-rate limit, the email system could allegedly be attacked using the response manipulation technique that attackers could leverage to bypass authentication.

Advertisement

"RailTel's mailing system was made in a very insecure way," Nehra told Gadgets 360. "Currently, it has turned the password reset page down."

The RailTel site was also using the Joomla version 3.4.2 that was released back in 2015. That particular release has been impacted by several known vulnerabilities.

Advertisement

Nehra said the site was impacted by a vulnerability that is tracked as CVE-2015-8562 and was exploited by some attackers in December 2015.

"The flaw leads to root access or complete hacking of the vulnerable server," he said, adding that other critical flaws of the outdated Joomla version also impacted the site.

Advertisement

To explain the flaws, Nehra shared three proof-of-concept (PoC) videos with Gadgets 360.

Shortly after spotting the issues, the researcher disclosed the vulnerabilities to RailTel and informed India's Computer Emergency Response Team (CERT-In) and National Critical Information Infrastructure Protection Centre (NCIIPC) on May 6. The CERT-In and NCIIPC last week confirmed to the researcher that the issues were patched by the enterprise.

RailTel also separately confirmed the fixes to Gadgets 360.

"RailTel's website runs behind a Web application firewall and is loaded with host-based antivirus and hence cyber attackers cannot exploit vulnerabilities, if any, and cannot upload shells to our website," the organisation said in a prepared statement emailed to Gadgets 360. "We would like to stress upon the fact that there has been NO INCIDENT of any data breach reported."

It also confirmed that its site was currently running on the latest stable release of Joomla platform.

"Also, currently we are not facing any issue related to the email account (railtelindia.com domain) compromise," it said.

RailTel runs a service called RailWire to offer free Wi-Fi access at railway stations in the country. It partnered with Google in 2016 to kick off a public Wi-Fi initiative called Google Station. The partnership, though, ended in May 2020. RailTel has, however, continued to provide free Wi-Fi service at hundreds of railway stations.

In 2017, the RailWire service was named as the worst affected service provider by the WannaCry ransomware by antivirus company eScan.

Aside from providing Internet access, RailTel in the recent past introduced technologies including an artificial intelligence (AI) based attendance system for government schools in Assam.


What is the best value flagship smartphone? We discuss this on Orbital, the Gadgets 360 podcast. Orbital is available on Spotify, Gaana, JioSaavn, Google Podcasts, Apple Podcasts, Amazon Music and wherever you get your podcasts.
Affiliate links may be automatically generated - see our ethics statement for details.
 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Google Pixel 10a Will Go on Sale in India via This E-Commerce Platform
  2. Microsoft Reportedly Working With OEMs to Build Affordable Xbox Consoles
  3. Apple Testing Two Key Camera Upgrades for iPhone 18 Pro Models
  4. Itel A100 4G Launched in India With 90Hz IPS Display, These Features
  5. Perplexity's New Feature Compares Answers From Three Different AI Models
  6. Nothing Phone 4a Series Launch Teased as Handsets Bag EEC Certification
  7. Poco X8 Pro Bags Another Certification, Hinting at Imminent Debut
  8. Boat Chrome Iris Launched in India With Up to Five Days of Battery Life
  1. Perplexity’s New Feature Compares Answers From Three Different AI Models
  2. Google Pixel 10a Flipkart Availability Confirmed After Company Announces Pre-Orders Date: Expected Specifications
  3. Telegram App for Android Gets Liquid Glass-Inspired Redesign With Bottom Navigation Bar
  4. Boat Chrome Iris Launched in India With 1.32-Inch AMOLED Display, Up to Five Days of Battery Life
  5. Itel A100 4G Launched in India With 90Hz IPS Display, 5,000mAh Battery: Price, Specifications
  6. Meta AI Could Reportedly Get New ‘Avocado’ Models, AI Agents and OpenClaw Integration
  7. Thalaivar Thambi Thalaimaiyil OTT Release Date: When and Where to Watch it Online?
  8. Kennedy OTT Release Date Confirmed: When and Where to Watch Sunny Leone Starrer Movie Online?
  9. The Roughneck OTT Release Date: When and Where to Watch This Thriller Film Online?
  10. Nothing Phone 4a Series Launch Teased as Handsets Receive EEC Certification: Expected Price, Features
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.