CBN CH6640E/CG6640E Wireless Gateway Series Multiple Vulnerabilities
The CBN modem gateway suffers from multiple vulnerabilities including authorization bypass information disclosure, stored XSS, CSRF and denial of Service. Default credentials are admin/admin and root/compalbn. An attacker can send a POST request to the URL http://192.168.0.1/goform/WifiDisconnect to cause a denial of service for all WiFi connected clients. An attacker can also set a cookie with userData=root or admin to reveal additional pages/info. An attacker can also send a POST request to the URL http://192.168.0.1/goform/WifiDisconnect to exploit the CSRF vulnerability. An attacker can also send a POST request to the URL http://192.168.0.1/goform/WifiDisconnect to exploit the stored XSS vulnerability.