# Exploit Title: Fastweb FASTgate 0.00.47 CSRF # Date: 09-05-2018 # Exploit Authors: Raffaele Sabato # Contact: https://twitter.com/syrion89 # Vendor: Fastweb # Product Web Page: http://www.fastweb.it/adsl-fibra-ottica/dettagli/modem-fastweb-fastgate/ # Version: 0.00.47 # CVE: CVE-2018-6023 I DESCRIPTION ======================================================================== An issue was discovered in Fastweb FASTgate 0.00.47 device. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify the configuration. This vulnerability may lead to Gues Wi-Fi activating, Wi-Fi password changing, etc. II PROOF OF CONCEPT ======================================================================== ## Activate Gues Wi-Fi:
III REFERENCES ======================================================================== http://www.fastweb.it/myfastpage/assistenza/guide/FASTGate/