CVE-2018-12529

HIGH

Intex N150 Firmware - Cross-Site Request Forgery

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2018-12529. PoCs published by Samrat Das.

AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Intex Router N-150 firmware, allowing an attacker to create a new admin user via a crafted HTML form. The lack of CSRF token validation enables arbitrary execution of privileged actions.

Description

An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.

Exploits (2)

exploitdb WORKING POC
by Samrat Das · textwebappshardware
https://www.exploit-db.com/exploits/44933

This exploit demonstrates a CSRF vulnerability in Intex Router N-150 firmware, allowing an attacker to create a new admin user via a crafted HTML form. The lack of CSRF token validation enables arbitrary execution of privileged actions.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Intex Router N-150
Auth required
Prerequisites: Victim must be logged into the router admin panel · Attacker must host the malicious HTML page and trick the victim into visiting it
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WRITEUP
by Samrat Das · textwebappshardware
https://www.exploit-db.com/exploits/44939

This exploit describes an arbitrary file upload vulnerability in the Intex Router N-150 firmware, allowing unauthorized file uploads via the backup-restore page, leading to a firmware reboot. The PoC lacks executable code but provides clear steps to reproduce the issue.

Classification
Writeup 80%
Attack Type
Other
Complexity
Trivial
Reliability
Reliable
Target: Intex Router N-150 firmware
Auth required
Prerequisites: Access to the router's admin interface · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit, Third Party Advisory
https://www.exploit-db.com/exploits/44933/
Exploit, Not Applicable, Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/44939/

Scores

CVSS v3 8.8
EPSS 0.0089
EPSS Percentile 54.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-352
Status published
Products (1)
intex/n150_firmware
Published Jul 02, 2018
Tracked Since Feb 18, 2026