CVE-2020-25988: A UPnP Abuse or, a feature.

So I was playing around with my home router and stumbled upon my first bug/feature. The bug/feature is: Once I’m on the same network (physical/wireless), I can login to your router’s admin panel, by fetching the credentials of ‘admin’ user.

Here’s a short writeup:

P.S. – If you have any feedback regarding anything or happen to spot any mistakes, please do let me know. Thanks!!


