PT-2024-28788 · Nepstech · Nepstech Wifi Router Xpon

Subhodeep Baroi

·

Published

2024-07-17

·

Updated

2024-08-01

·

CVE-2024-40119

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN version 1.0 Firmware V2.0.1
Description The issue concerns a Cross-Site Request Forgery (CSRF) vulnerability in the password change function. This allows remote attackers to change the admin password without the user's consent, potentially leading to account takeover.
Recommendations For Nepstech Wifi Router xpon (terminal) model NTPL-Xpon1GFEVN version 1.0 Firmware V2.0.1, consider disabling the password change function temporarily until a patch is available to prevent potential account takeover. Restrict access to the password change module to minimize the risk of exploitation. Avoid using the password change feature in the affected firmware version until the issue is resolved.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2024-40119

Affected Products

Nepstech Wifi Router Xpon