vendor:
N/A
by:
Anonymous
8.8
CVSS
HIGH
Authentication Bypass
287
CWE
Product Name: N/A
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2020
Router Password Change Exploit
This exploit allows an attacker to change the password of a router without authentication. The exploit uses a POST request to the router's mod__login.asp page with the new password in the data parameter. The exploit is possible due to the lack of authentication on the router's mod__login.asp page.
Mitigation:
Ensure that authentication is required for all requests to the router's mod__login.asp page.