[COLOR="#000000"][COLOR="#0000BB"]Access to the Config file without authentication[/COLOR][COLOR="#007700"]=>[/COLOR][COLOR="#0000BB"]full authentication bypass possible[/COLOR][COLOR="#007700"]!:):([/COLOR][COLOR="#0000BB"]1[/COLOR][COLOR="#007700"])
=>[/COLOR][COLOR="#0000BB"]sysPassword is Base64 encoded
[/COLOR][COLOR="#007700"]*[/COLOR][COLOR="#0000BB"]Access to the logfile without authentication[/COLOR][COLOR="#007700"]:([/COLOR][COLOR="#0000BB"]1[/COLOR][COLOR="#007700"])
[/COLOR][COLOR="#007700"]*[/COLOR][COLOR="#0000BB"]Change the DNS Settings without authentication[/COLOR][COLOR="#007700"]:([/COLOR][COLOR="#0000BB"]1[/COLOR][COLOR="#007700"])
[/COLOR][COLOR="#007700"]*[/COLOR][COLOR="#0000BB"]Stored XSS within parental control[/COLOR][COLOR="#007700"]([/COLOR][COLOR="#0000BB"]2[/COLOR][COLOR="#007700"]):
[/COLOR][COLOR="#0000BB"]Again you are able to place this XSS without authentication[/COLOR][COLOR="#007700"].:)
*[/COLOR][COLOR="#0000BB"]Login Credentials in HTTP GET are not a good idea[/COLOR][COLOR="#007700"]=> use[/COLOR][COLOR="#0000BB"]HTTP Post[/COLOR][COLOR="#007700"]!([/COLOR][COLOR="#0000BB"]3[/COLOR][COLOR="#007700"])
[/COLOR][COLOR="#007700"]*[/COLOR][COLOR="#0000BB"]Credentials in HTTP GET via password change request are not a good idea[/COLOR][COLOR="#007700"]=> use[/COLOR][COLOR="#0000BB"]HTTP Post[/COLOR][COLOR="#007700"]!:([/COLOR][COLOR="#0000BB"]3[/COLOR][COLOR="#007700"])