Skip to content

Latest commit

 

History

History
18 lines (10 loc) · 829 Bytes

SetAutoRebootSettings.md

File metadata and controls

18 lines (10 loc) · 829 Bytes

Overview

Affected version

DIR823G_V1.0.2B05_20181207

Vulnerability details

An improper access control vulnerability exists in the web management interface of DIR823G_V1.0.2B05_20181207. By sending a specially crafted unauthenticated HTTP POST request to the /HNAP1/ endpoint with the SOAPAction header set to SetAutoRebootSettings, an attacker can set the auto reboot settings of the device.

POC

image-20241223132327215

image-20241223132342280