vendor:
F@ST 2604
by:
KinG Of PiraTeS
6,8
CVSS
MEDIUM
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: F@ST 2604
Affected Version From: 253180972B
Affected Version To: 253180972B
Patch Exists: NO
Related CWE: NA
CPE: h:sagem:fast_2604
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2020
Sagem F@ST 2604 CSRF Vulnerability (ADSL Router)
From SAGEM F@st 2604 U can change the default 'Admin' password Or Any User Password which is listening on tcp/ip port 80. An exploit is provided which uses a malicious HTML page to change the password to '123123'.
Mitigation:
Ensure that the router is not exposed to the public internet and that access to the router is restricted to trusted users.