vendor:
ADSL Router DL4322D
by:
Cakes
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: ADSL Router DL4322D
Affected Version From: RTK 2.1.1
Affected Version To: RTK 2.1.1
Patch Exists: NO
Related CWE: N/A
CPE: h:netis:adsl_router_dl4322d
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Kali Linux
2018
Netis ADSL Router DL4322D RTK 2.1.1 – Cross-Site Request Forgery (Add Admin)
Due to improper session management an attacker is able to add a administrator account without providing any authentication credentials.
Mitigation:
Implement proper session management and authentication.