ASUS RT-N16 - Text-plain Admin... CVE-2013-3093

9.3 AV AC AU C I A
发布: 2020-01-28
修订: 2020-01-31

Description ----------- Several ASUS routers include reflected Cross-Site Scripting (CWE-79) and authentication bypass (CWE-592) vulnerabilities. An attacker who can lure a victim to browse to a web site containing a specially crafted JavaScript payload can execute arbitrary commands on the router as administrator (root). No user interaction is required. Impact ------ An attacker can create a JavaScript payload that uses an exploit to unearth the administrative password from the victim's ASUS router and logs in to the device. Once logged in the payload can perform administrative actions, including arbitrary command execution as administrator (root). Details ------- The CSRF vulnerability CVE-2013-3093 discovered by Jacob Holcomb / Independent Security Evaluators (*) affecting various ASUS routers has been known for some time. The vulnerability enables an attacker to forge HTML forms and execute actions on the behalf of the target user (admin), enabling executing administrative...

0%
暂无可用Exp或PoC
当前有14条受影响产品信息