vendor:
ADSL SL2-141 Router
by:
Binary Vision
8.8
CVSS
HIGH
Cross-Site Request Forgery (CSRF)
352
CWE
Product Name: ADSL SL2-141 Router
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2020
Siemens ADSL SL2-141 (Router) CSRF Exploit
This exploit allows remote access to the router over the internet by bruteforcing the random security number. It uses the default login credentials (Admin:Admin) and could use a dictionary instead. The PoC only, there are much more effective ways of doing this.
Mitigation:
Implementing proper authentication and authorization mechanisms, as well as input validation, can help mitigate the risk of CSRF attacks.