iBall WRB303N devices allow CSRF attacks, as demonstrated by enabling remote management, enabling DHCP, or modifying the subnet range for IP addresses.
https://github.com/Saket-taneja/IballCSRFExploit
https://gist.github.com/Saket-taneja/4dda4b2df5aa0973a7160bb6bf8875e0