Edb-id: 45034 Author: LiquidWorm Type: WebApps Date: 2018-07-17 Platform: Hardware Vulnerable App: Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway Key Vulnerability Information: Description: CSRF vulnerability in Microhard Systems 3G/4G Cellular Ethernet and Serial Gateway allows a logged-in user to perform certain actions with administrative privileges if they visit a malicious URL. Affected Versions: - IPn4G 1.1.0 build 1098 - IPn3Gb 2.2.0 build 2160 - IPn4Gb 1.1.6 build 1184-14 - IPn4Gb 1.1.0 Rev 2 build 1090-2 - IPn4Gb 1.1.0 Rev 2 build 1086 - Bullet-3G 1.2.0 Rev A build 1032 Exploit Details: CSRF Change Admin Password: A malicious form submission can change the admin password due to lack of CSRF protection. CSRF Add Admin User: A form can be submitted to add a new admin user, leveraging the CSRF vulnerability. Vulnerability Discovered by: Gjoko Krstic 'LiquidWorm'