securitywarrior9.blogspot.com
http://securitywarrior9.blogspot.com/2018/06/malicious-file-upload-intex-router-n.html CVE-2018-12528
HIGH
Intex Router N-150 - Cross-Site Request Forgery (Add Admin)
Record summary
CVE-2018-12528 has a selected CVSS score of 8.1 (high); EIP currently links 1 catalogued exploit.
Description
An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration files backup, which can lead to corrupting the router firmware settings or even the uploading of malicious files. In order to exploit the vulnerability, an attacker can upload any malicious file and force reboot the router with it.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBIntex Router N-150 - Cross-Site Request Forgery (Add Admin)ExploitDB exploitby Samrat DasNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-12528 44933exploit
https://www.exploit-db.com/exploits/44933