CVE-2019-6710
HIGHZyxel NBG-418N v2 v1.00(AAXM.4)C0 - Cross-Site Request Forgery via login.cgi
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-6710. PoCs published by Ali Can Gönüllü.
AI-analyzed exploit summary This is a CSRF exploit targeting Zyxel NBG-418N v2 modems, allowing an attacker to trick a logged-in admin into submitting a login form to change credentials or perform other actions. The PoC demonstrates a simple HTML form that submits credentials to the modem's login endpoint.
Description
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
Exploits (1)
This is a CSRF exploit targeting Zyxel NBG-418N v2 modems, allowing an attacker to trick a logged-in admin into submitting a login form to change credentials or perform other actions. The PoC demonstrates a simple HTML form that submits credentials to the modem's login endpoint.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H