Title: PLC Wireless Router GPN2.4P21-C-CN - Incorrect Access Control EDB-ID: 46580 CVE: 2019-6279 Author: Kumar Saurav Type: WEBAPPS Platform: HARDWARE Date: 2019-03-20 Vulnerable App: ChinaMobile PLC Wireless Router GPN2.4P21-C-CN (Firmware: W2001EN-00) Description ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have an Incorrect Access Control vulnerability via the cgi-bin/webproc?getpage=html/index.html subpage=wlsecurity URI, allowing an attacker to change the wireless security password. Reproduction Steps 1. Build a malicious HTML web page. 2. Attackers can change the wireless security (WPA/WPA2) key using a specific password. 3. Use the following form to submit the exploit: 4. Save as . 5. Plant this malicious web page; it can be accessed by anyone connected to the AP. 6. After execution, the wireless security key will change. Note This vulnerability allows an attacker to reproduce the issue without login. Tags Authentication Bypass / Credentials Bypass (AB/CB)