CVE-2014-3792
Beetel 450TC2 Router Firmware TX6-0Q-005_retail - Cross-Site Request Forgery via Password Change
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-3792. PoCs published by shyamkumar somana.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Beetel 450TC2 routers, allowing an attacker to change the admin password without user interaction via a crafted HTML form. The PoC submits a POST request to the vulnerable endpoint with new password values.
Description
Cross-site request forgery (CSRF) vulnerability in Beetel 450TC2 Router with firmware TX6-0Q-005_retail allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via the uiViewTools_Password and uiViewTools_PasswordConfirm parameters to Forms/tools_admin_1.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Beetel 450TC2 routers, allowing an attacker to change the admin password without user interaction via a crafted HTML form. The PoC submits a POST request to the vulnerable endpoint with new password values.