PT-2018-10772 · Tp Link · Tp-Link Tl-Wr841N+1

Publicado

2018-06-04

·

Atualizado

2018-07-31

·

CVE-2018-11714

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link TL-WR840N version 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n TP-Link TL-WR841N version 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n
Description The issue is caused by improper session handling on the "/cgi/" folder or a "/cgi" file. An attacker can exploit this by sending a header of "Referer: http://192.168.0.1/mainFrame.htm", which allows them to perform any action without requiring authentication.
Recommendations For TP-Link TL-WR840N version 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n, restrict access to the /cgi/ folder to minimize the risk of exploitation. For TP-Link TL-WR841N version 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n, avoid using the "/cgi/" folder until the issue is resolved.

Exploit

Correção

Session Fixation

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-11714

Produtos afetados

Tp-Link Tl-Wr840N
Tp-Link Tl-Wr841N