# Exploit Title: DODOCOOL DC38 N300 Cross-site Request Forgery # Date: 17-01-2018 # Exploit Authors: Raffaele Sabato # Contact: https://twitter.com/syrion89 # Vendor: DODOCOOL # Vendor Homepage: www.dodocool.com # Version: RTN2-AW.GD.R3465.1.20161103 # CVE: CVE-2018-5720 I DESCRIPTION ======================================================================== An issue was discovered in DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify the configuration. This vulnerability may lead to username and/or password changing, Wi-Fi password changing, etc. II PROOF OF CONCEPT ======================================================================== ## Change user username and password (test_username:test_password):
## Change WiFi Configuration (WIFI_TEST:TestTest):