CVE-2024-40119
HIGHNepstech Wifi Router xpon NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 - Cross-Site Request Forgery in Password Change Function
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2024-40119. PoCs published by baroi-ai.
AI-analyzed exploit summary This repository contains a functional CSRF exploit for CVE-2024-40119, targeting the Nepstech Wifi Router NTPL-XPON1GFEVN v1.0. The PoC includes an HTML form that submits a crafted POST request to change the admin password without user interaction.
Description
Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN v.1.0 Firmware V2.0.1 contains a Cross-Site Request Forgery (CSRF) vulnerability in the password change function, which allows remote attackers to change the admin password without the user's consent, leading to a potential account takeover.
Exploits (1)
This repository contains a functional CSRF exploit for CVE-2024-40119, targeting the Nepstech Wifi Router NTPL-XPON1GFEVN v1.0. The PoC includes an HTML form that submits a crafted POST request to change the admin password without user interaction.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H