vendor:
Platinum-4410
by:
Mohammed Farhan
6.8
CVSS
MEDIUM
Cross Site Request Forgery
352
CWE
Product Name: Platinum-4410
Affected Version From: P4410-V2-1.28
Affected Version To: P4410-V2-1.28
Patch Exists: NO
Related CWE: N/A
CPE: genexis.co.in/product/ont/
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2020
Genexis Platinum-4410 P4410-V2-1.28 – Cross Site Request Forgery to Reboot
Login to the application and create an HTML file using the code provided. Open the HTML page in the browser and click on 'Submit Request'. This will cause the modem to reboot.
Mitigation:
Implementing a strong authentication mechanism and validating all input data.