andhwa.blogg.se

Zte zxv10 w300 firmware update download
Zte zxv10 w300 firmware update download







zte zxv10 w300 firmware update download

The Exploit Database is maintained by Offensive Security, an information security training company You can see my previous post about this vulnerability and the exploit. Ofcourse since there is no XSRF token in the request you change the password as you wish. If you send something like above to the victim, he will be prompted for the login and once he enter his credentials, his password will be immediately changed to a blank password. You can change the password to blank by requesting /Forms/tools_admin_1 with a GET requesting containing HTTP basic authentication.

zte zxv10 w300 firmware update download

#4| Admin Password Manipulation CSRF (CVE-2014-4155) Once the user authenticates the router till another successful restart the password is written in that external JS file. The "pwdpp" is loaded from an external file which you can see at the bottom of the page.

zte zxv10 w300 firmware update download

If(_PPPPassword != null)ĭ_PPPPassword.value = pwdppp If you look at the frame source in the "Internet" tab under the "Interface Setup" you can see this doLoad function in line 542 which fetches the password and displays it there. #3| PPPoE/PPPoA Password Disclosure in tc2wanfun.js (CVE-2014-4154) You can find the router password using my rom-0 configuration decompressor. There is a disclosure in which anyone can download that file without any authentication by a simple GET request. The rom-0 backup file contains sensitive information such as the router password. In ZTE routers the username is a constant which is "admin" and the password by default is "admin" #1| Default Password Being Used (CVE-2014-4018) # Exploit Author: Osanda Malith Jayathissa Original write-up: # Exploit Title: ZTE WXV10 W300 Multiple Vulnerabilities









Zte zxv10 w300 firmware update download