vendor:
iPuppy, iPuppy3, N100RE and N200RE
by:
Pierre Kim
7.5
CVSS
HIGH
CSRF and XSS attacks
352, 79
CWE
Product Name: iPuppy, iPuppy3, N100RE and N200RE
Affected Version From: 1.2.2001
Affected Version To: 1.4-B20140724-2-457-EN
Patch Exists: No
Related CWE: No current CVE
CPE: TOTOLINK
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2015
4 TOTOLINK router models vulnerable to CSRF and XSS attacks
TOTOLINK iPuppy, iPuppy3, N100RE and N200RE are wireless LAN routers. Their current firmwares with default configuration are vulnerable to CSRF-attacks and XSS attacks. Since, the anti-CSRF protection is based on a static HTTP referrer (RFC 1945), an attacker can take over most of the configuration and settings using anyone inside the LAN of the router.
Mitigation:
Activate authentication on this product (disabled by default)