A weak password reset mechanism in Araknis Networks routers allows an attacker to manipulate HTTP requests or client-side code to bypass authentication and reset device credentials — gaining full control of the router and the network it manages.
The vulnerability involves insecure restrictions on the password reset form in the web management interface. Attackers can use crafted in-browser code manipulation to alter client-side validation and submit password reset requests that the router incorrectly fulfills.
Full administrative control of the network router, including firewall rules, routing configuration, DNS settings, and connected device visibility.
Redinent Vikron's firmware-level analysis identifies authentication bypass patterns across your entire device fleet — without manual testing.