vendor:
450TC2
by:
shyamkumar somana
7,5
CVSS
HIGH
Cross Site Request Forgery
352
CWE
Product Name: 450TC2
Affected Version From: 450TC2 - Firmware version : TX6-0Q-005_retail
Affected Version To: 450TC2 - Firmware version : TX6-0Q-005_retail
Patch Exists: NO
Related CWE: N/A
CPE: h:beetel:450tc2
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 8
2014
Beetel 450TC2 Router Admin Password Cross Site Request Forgery Vulnerability
Beetel 450TC2 Router is vulnerable for cross site request forgery vulnerability in change password page. An attacker can exploit this vulnerability by sending a malicious POST request to the Forms/tools_admin_1 page with the new password in the request body. This will allow the attacker to change the router's admin password without authentication.
Mitigation:
The router should be configured to only accept authenticated requests to the Forms/tools_admin_1 page.