CVE-2013-5218
HOT HOTBOX Router Firmware 2.1.11 - Cross-Site Scripting via DHCP Host Name Option
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2013-5218.
AI-analyzed exploit summary The provided code includes a CSRF exploit and a DoS exploit targeting the HOTBOX router/modem (SAGEMCOM F@st 3184). The CSRF exploit manipulates wireless settings via a crafted HTML form, while the DoS exploit sends a malformed POST request to crash the device.
Description
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.
Exploits (1)
The provided code includes a CSRF exploit and a DoS exploit targeting the HOTBOX router/modem (SAGEMCOM F@st 3184). The CSRF exploit manipulates wireless settings via a crafted HTML form, while the DoS exploit sends a malformed POST request to crash the device.