Exploits / Vulnerability Discovered : 2018-03-20 |
Type : webapps |
Platform : hardware
This exploit / vulnerability Coship rt3052 wireless router persistent crosssite scripting is for educational purposes only and if it is used you will do on your own risk!
Reproduction Steps:
------------------------------
1. Access the wifi router gateway [i.e, http://192.168.1.254]
2. Go to "Wireless Setting" -> "Basic"
3. Update "Network Name(SSID)" field with '<script>alert("S@Y@N")</script>'
4. Save the settings.
5. Go to "System Status" and you will be having "S@Y@N" popup.