Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2017-6896

Description

Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from user privilege to admin privilege just by modifying the Base64-encoded session cookie value.

POC

Reference

- http://seclists.org/fulldisclosure/2017/Mar/52

- https://drive.google.com/file/d/0B6715xUqH18MX29uRlpaSVJ4OTA/view?usp=sharing

- https://packetstormsecurity.com/files/141693/digisol-escalate.txt

- https://www.exploit-db.com/exploits/41633/

Github

No PoCs found on GitHub currently.