PT-2018-3322 · Tp Link · Tp-Link Tl-R600Vpn
CVE-2018-3950
·
Publicado
2018-11-19
·
Atualizado
2023-02-03
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-R600VPN versions HWv3 FRNv1.3.0 and HWv2 FRNv1.2.3
Description
A remote code execution issue exists in the ping and tracert functionality of the TP-Link TL-R600VPN http server. This is caused by a stack overflow resulting from a specially crafted IP address. An attacker can trigger this issue by sending a single authenticated HTTP request, potentially allowing remote code execution.
Recommendations
For TP-Link TL-R600VPN version HWv3 FRNv1.3.0, consider disabling the ping and tracert functionality until a patch is available.
For TP-Link TL-R600VPN version HWv2 FRNv1.2.3, restrict access to the http server to minimize the risk of exploitation.
Exploit
Correção
Buffer Overflow
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Tp-Link Tl-R600Vpn