Subscribe via feed.

devolo dLAN 550 duo+ 3.1.0-1 Starter Kit Cross-Site Request Forgery

Posted by deepcore on February 5, 2019 – 1:35 pm

devolo dLAN 550 duo+ version 3.1.0-1 allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. The devolo web application uses predictable URL/form actions in a repeatable way. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.


This post is under “exploit” and has no respond so far.
If you enjoy this article, make sure you subscribe to my RSS Feed.

Post a reply

You must be logged in to post a comment.