Cross-Site Request Forgery Vulnerability in Beetel Router by Beetel
CVE-2014-3792

Currently unrated

Key Information:

Vendor

Beetel

Vendor
CVE Published:
20 May 2014

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2014-3792?

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Beetel 450TC2 Router with firmware TX6-0Q-005_retail. This flaw permits remote attackers to exploit the router's web interface, hijacking the session of an authenticated administrator to change sensitive settings, such as the administrator password. By targeting the uiViewTools_Password and uiViewTools_PasswordConfirm parameters, attackers can craft malicious requests that manipulate the administrator settings without the victim's consent, leading to unauthorized access and control of the device.

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • Vulnerability Reserved

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

.