vendor:
N150 Wireless Home Router
by:
Rahul Pratap Singh
7,5
CVSS
HIGH
HTML/Script Injection, Session Hijacking
79, 384
CWE
Product Name: N150 Wireless Home Router
Affected Version From: F9K1009 v1
Affected Version To: F9K1009 v1
Patch Exists: NO
Related CWE: N/A
CPE: h:belkin:n150_wireless_home_router
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2015
Belkin N150 Wireless Home Router Multiple Vulnerabilities
The Belkin N150 Wireless Home Router is vulnerable to HTML/Script Injection and Session Hijacking. The parameter 'InternetGatewayDevice.DeviceInfo.X_TWSZ-COM_Language' is vulnerable to HTML/Script Injection, and the sessionid cookie is vulnerable to Session Hijacking. The sessionid is allocated using hex encoding and of fixed length i.e 8, and can be bruteforced using the range 00000000 to ffffffff.
Mitigation:
Ensure that user input is properly sanitized and validated, and that sessionid cookies are not easily guessable.