vendor:
Intelbras Router RF 301K
by:
Rodolfo Mariano
8.8
CVSS
HIGH
DNS Hijacking
200
CWE
Product Name: Intelbras Router RF 301K
Affected Version From: Firmware 1.1.2
Affected Version To: Firmware 1.1.5
Patch Exists: YES
Related CWE: CVE-2021-32403
CPE: h:intelbras:router_rf_301k
Platforms Tested:
2021
Intelbras Router RF 301K – ‘DNS Hijacking’ Cross-Site Request Forgery (CSRF)
This exploit allows an attacker to perform a Cross-Site Request Forgery (CSRF) attack on the Intelbras Router RF 301K. By submitting a specially crafted form, the attacker can change the router's DNS settings, redirecting traffic to a malicious DNS server.
Mitigation:
To mitigate this vulnerability, it is recommended to update the router's firmware to version 1.1.6 or later. Additionally, users should regularly change the default credentials and disable remote management.