vendor:
WZR-HP-G300NH2
by:
Prayas Kulshrestha
8,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: WZR-HP-G300NH2
Affected Version From: DD-WRT v24SP2-MULTI (10/31/11) std - build 17798
Affected Version To: DD-WRT v24SP2-MULTI (10/31/11) std - build 17798
Patch Exists: NO
Related CWE: N/A
CPE: h:buffalo:wzr-hp-g300nh2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 (ultimate) 64-bit
2013
Buffalo WZR-HP-G300NH2 CSRF Vulnerability
There is a CSRF vulnerability in the Buffalo WZR-HP-G300NH2 and any one easily change or manipulate the admin username and password. This is will POST request and any one can craft malicious html form with specially crafted POST request to the router and on execution of the form the router's user name and password can be changed to anything.
Mitigation:
Implementing a strong authentication mechanism and using a secure token for authentication.