iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15043
Reference (s):
- https://gist.github.com/Saket-taneja/4dda4b2df5aa0973a7160bb6bf8875e0
- https://github.com/Saket-taneja/IballCSRFExploit

