An issue in Planet Technologies WDRT-1800AX v1.01-CP21 allows attackers to bypass authentication and escalate privileges to root via manipulation of the LoginStatus cookie.
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Link | Tags |
---|---|
https://github.com/0xfml/poc/blob/main/PLANET/WDRT-1800AX.md | third party advisory exploit |
https://www.planet.com.tw/en/product/wdrt-1800ax | product |