########################################################### [~] Exploit Title: DPR2320R2 [Scientific-Atlanta, Inc.(A Cisco COMPANY)] :: Multiple CSRF vulnerability [~] Author: sajith [~]Category: Hardware/Wireless Router [~] vendor home page: http://www.cisco.com/web/consumer/support/modem_DPR2320.html [~] Software Version: v2.0.2r1262-090417 ########################################################### (1) Attacker can change the modem authentication password using CSRF vulnerability .check the below POC POC by sajith shetty
(2)Attacker can reboot modem using CSRF vulnerability(check below POC) POC by sajith shetty
(3)wireless settings can be exploited using CSRF vulnerability.below POC shows how password is changed for n/w authentication WPA-PSK with WPA-encryption set to TKIP(these setting can also be changed) POC by sajith shetty
(4)Parental control set up can be disabled or password set for parental set up can be changed by CSRF vulnerability[POC shown below] POC by sajith shetty