packetstormsecurity.com
http://packetstormsecurity.com/files/159936/Genexis-Platinum-4410-P4410-V2-1.28-Missing-Access-Control-CSRF.html CVE-2020-25015
MEDIUM
Genexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRF
Record summary
CVE-2020-25015 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.
Description
A specific router allows changing the Wi-Fi password remotely. Genexis Platinum 4410 V2-1.28, a compact router generally used at homes and offices was found to be vulnerable to Broken Access Control and CSRF which could be combined to remotely change the WIFI access point’s password.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBGenexis Platinum-4410 P4410-V2-1.28 - Broken Access Control and CSRFExploitDB exploitby Jinson Varghese BehananNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-25015 getastra.com
https://www.getastra.com/blog/911/csrf-broken-access-control-in-genexis-platinum-4410 jinsonvarghese.com
https://www.jinsonvarghese.com/broken-access-control-csrf-in-genexis-platinum-4410