This POC demonstrates how to execute commands on the DGN2200 router (having Bezeq's firmware).
It demonstrates three vulnerabilities:
-
Command injection.
-
Authorization bypass.
-
CSRF.
Of course, using CSRF, a malicious attacker can make the victim run arbitrary commands on the router.