Exploitation Summary
EIP tracks 1 public exploit for CVE-2015-5996. PoCs published by Nathu Nandwani.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Tenda Wireless N150 Router 5.07.50, allowing an attacker to reboot the router by tricking an authenticated administrator into visiting a malicious webpage. The PoC sets up a simple HTTP server that serves a crafted HTML form which automatically submits to the router's reboot endpoint.
Description
Cross-site request forgery (CSRF) vulnerability on Mediabridge Medialink MWN-WAPR300N devices with firmware 5.07.50 allows remote attackers to hijack the authentication of arbitrary users.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in Tenda Wireless N150 Router 5.07.50, allowing an attacker to reboot the router by tricking an authenticated administrator into visiting a malicious webpage. The PoC sets up a simple HTTP server that serves a crafted HTML form which automatically submits to the router's reboot endpoint.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H