Overview

Affected version

FH1202 V1.2.0.14(408)

Vulnerability details

An improper access control vulnerability exists in the web management interface of In FH1202 V1.2.0.14(408). By sending a specially crafted unauthenticated HTTP POST request to the goform endpoint with AdvSetWrlGstset, an attacker can set the ssid settings of the device.

POC

image.png