Turcom TRCwifiZone through 2020-08-10 allows authentication bypass by visiting manage/control.php and ignoring 302 Redirect responses.
The code contains a control flow path that does not reflect the algorithm that the path is intended to implement, leading to incorrect behavior any time this path is navigated.
Link | Tags |
---|---|
https://www.turcom.com.tr/en/urunlerimiz-sorunsuz-internet-trcwifizone.asp | product vendor advisory |
https://cxsecurity.com/issue/WLB-2020080046 | third party advisory exploit |