# Exploit Title: Verizon Fios Router CSRF Admin Shell # Date: Discovered and reported January 2013 # Author: Jacob Holcomb/Gimppy - Security Analyst @ Independent Security Evaluators # Software: Verizon FIOS Router - Firmware 40.19.36 (http://verizon.com) # CVE: CVE-2013-0126 # Advisory/Video: http://infosec42.blogspot.com/2013/03/verizon-fios-router-csrf-cve-2013-0126.html US CERT Disclosure: http://www.kb.cert.org/vuls/id/278204 Exploit Code: HTML FILE #1 Cisco Verizon FIOS CSRF - Adding Administrator User

Please sit tight while we upgrade your router

HTML FILE #2 Cisco Verizon FIOS CSRF2 - Add User w/ No Pass Confirmation
HTML FILE #3 Cisco Verizon FIOS CSRF3 - Enable Remote Administration