vendor:
GPON ONT WiFi Router H64X Series
by:
Gjoko 'LiquidWorm' Krstic
7,5
CVSS
HIGH
Privilege Escalation
264
CWE
Product Name: GPON ONT WiFi Router H64X Series
Affected Version From: 2.77-1115
Affected Version To: 2.45-1045
Patch Exists: YES
Related CWE: N/A
CPE: h:dasan_networks:h640gr-02
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: lighttpd/1.4.31, DasanNetwork Solution
2017
Dasan Networks GPON ONT WiFi Router H64X Series Privilege Escalation
The application suffers from a privilege escalation vulnerability. A normal user can elevate his/her privileges by changing the Cookie 'Grant' from 1 (user) to 2 (admin) gaining administrative privileges and revealing additional functionalities or additional advanced menu settings.
Mitigation:
Ensure that the application is configured to use secure authentication and authorization mechanisms.