Description
Ubee EVW327 contains a cross-site request forgery vulnerability that allows attackers to enable remote access without user interaction. Attackers can craft a malicious webpage that automatically submits a form to change router remote access settings to port 8080 without the user's consent.
Problem types
Cross-Site Request Forgery (CSRF)
Product status
Credits
lated
References
www.exploit-db.com/exploits/49920 (ExploitDB-49920)
www.ubeeinteractive.com (Ubee Interactive Official Homepage)
www.vulncheck.com/...-access-cross-site-request-forgery-csrf (VulnCheck Advisory: Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF))