vendor:
N-150
by:
Navina Asrani
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: N-150
Affected Version From: N-150
Affected Version To: N-150
Patch Exists: YES
Related CWE: N/A
CPE: h:intex:n-150
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
Intex Router N-150 – Cross-Site Request Forgery (Add Admin)
The firmware allows malicious request to be executed without verifying source of request. This leads to arbitrary execution with malicious request which will lead to the creation of a privileged user.
Mitigation:
Implementing CSRF tokens to verify the source of the request.