Exploitation Summary
EIP tracks 2 public exploits for CVE-2018-12529. PoCs published by Samrat Das.
AI-analyzed exploit summary This exploit demonstrates a CSRF vulnerability in Intex Router N-150 firmware, allowing an attacker to create a new admin user via a crafted HTML form. The lack of CSRF token validation enables arbitrary execution of privileged actions.
Description
An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.
Exploits (2)
This exploit demonstrates a CSRF vulnerability in Intex Router N-150 firmware, allowing an attacker to create a new admin user via a crafted HTML form. The lack of CSRF token validation enables arbitrary execution of privileged actions.
This exploit describes an arbitrary file upload vulnerability in the Intex Router N-150 firmware, allowing unauthorized file uploads via the backup-restore page, leading to a firmware reboot. The PoC lacks executable code but provides clear steps to reproduce the issue.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H