On Netis DL4323 devices, CSRF exists via form2logaction.cgi to delete all logs.
The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.
Link | Tags |
---|---|
https://drive.google.com/open?id=1XtSsH-1ApxRS7VExubz8zBEyENVQGhUc | third party advisory exploit |
https://drive.google.com/open?id=1p4HJ5C20TqY0rVNffdD5Zd7S_bGvDhnk | third party advisory exploit |
https://fatihhcelik.blogspot.com/2019/12/csrf-vulnerability-on-clean-log-netis.html | third party advisory exploit |