CVE-2016-7454
HIGHTechnicolor Xfinity Gateway Router DPC3941T Firmware CSRF Vulnerability
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2016-7454. PoCs published by Ayushman Dutta.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in the XFINITY Gateway Technicolor DPC3941T router, allowing an attacker to change the WiFi password via a crafted HTML page with JavaScript. The PoC sends a POST request to the vulnerable endpoint without requiring authentication.
Description
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r20421733-160413a-CMCST allows an attacker to change the Wi-Fi password, open the remote management interface, or reset the router.
Exploits (1)
This exploit demonstrates a CSRF vulnerability in the XFINITY Gateway Technicolor DPC3941T router, allowing an attacker to change the WiFi password via a crafted HTML page with JavaScript. The PoC sends a POST request to the vulnerable endpoint without requiring authentication.
References (2)
Scores
CVSS:3.0/AV:A/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H