Improper access control on the LocalMACConfig.asp interface allows an unauthenticated remote attacker to add (or remove) client MAC addresses to (or from) a list of banned hosts. Clients with those MAC addresses are then prevented from accessing either the WAN or the router itself.
Link | Tags |
---|---|
https://www.tenable.com/security/research/tra-2022-01 | third party advisory exploit |