5 ms·
Doesn't the target need to have an active router admin session for the CSRF to work? Unless I'm missing something...
by prez 12y ago
Doesn't the target need to have an active router admin session for the CSRF to work?
Unless I'm missing something...
- pizzeys 12y agoI don't know about this specific bug, but there have been consumer routers bugs before (Netgear specifically) where not only were they vulnerable to CSRF, but authentication bypass at the same time if the request was crafted carefully.
- bartbes 12y agoUPnP is made to have application automatically open ports without being logged into the web config.