Authored by Matteo Mandolini

Aigital Wireless-N Repeater version Mini_Router.0.131229 suffers from a login bypass vulnerability.

# Exploit Title: Aigital Wireless-N Repeater - Login Bypass
# Exploit Author: Matteo Mandolini
# Date : 13/04/2023
# Vendor Homepage: https://web.archive.org/web/20220625053314/https://www.aigital.com/
# Version: Mini_Router.0.131229

Login bypass

The device web application relies on a time-based mechanism to manage authentications. From the moment a legitimate user logs into the application with his or her credentials, any other user who can reach the web application is able to bypass the login and directly access the application's functionalities until the legitimate user's session expires.