vendor:
WB-3300NR
by:
absane
7,8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: WB-3300NR
Affected Version From: V5.07.18_ko_UIS02
Affected Version To: V5.07.18_ko_UIS02
Patch Exists: NO
Related CWE: N/A
CPE: h:unicorn:wb-3300nr
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Unicorn Router WB-3300NR CSRF (Factory Reset/DNS Change)
The WB-3300NR Unicorn Router suffers from numerous CSRF vulnerabilities. Considering that by default the administrative pages do not require authentication, countless exploits exist. The PoC code demonstrates that with CSRF and XSS, it might be possible to obtain the WPA password.
Mitigation:
Enabling authentication for administrative pages and implementing CSRF protection.