Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
BID:27374
Info
Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 27374 |
| Class: | Design Error |
| CVE: |
CVE-2008-7165 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 21 2008 12:00AM |
| Updated: | May 07 2015 05:33PM |
| Credit: | WarGame/DoomRiderz is credited with the discovery of this vulnerability. |
| Vulnerable: |
Alice.it Alice Gate2 Plus Wi-Fi 0 |
| Not Vulnerable: | |
Discussion
Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
Alice Gate2 Plus Wi-Fi routers are prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to alter administrative configuration on affected devices. Specifically, altering the wireless encryption settings on devices has been demonstrated. Other attacks may also be possible.
Alice Gate2 Plus Wi-Fi routers are prone to a cross-site request-forgery vulnerability.
An attacker can exploit this issue to alter administrative configuration on affected devices. Specifically, altering the wireless encryption settings on devices has been demonstrated. Other attacks may also be possible.
Exploit / POC
Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI will disable wireless encryption on affected devices:
http://www.example.com/cp06_wifi_m_nocifr.cgi?wlChannel=Auto&wlRadioEnable=on
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following example URI will disable wireless encryption on affected devices:
http://www.example.com/cp06_wifi_m_nocifr.cgi?wlChannel=Auto&wlRadioEnable=on
Solution / Fix
Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Alice Gate2 Plus Wi-Fi Router Cross-Site Request Forgery Vulnerability
References:
References: