PT-2019-4122 · Tp Link · Tp-Link Tl-Wr840N

Rapt00R

·

Publicado

2019-08-22

·

Atualizado

2020-08-24

·

CVE-2019-15060

CVSS v2.0

9.0

Alta

VetorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link TL-WR840N version 0.9.1 3.16 and earlier
Description The issue concerns the traceroute function, which is vulnerable to remote code execution. This can be achieved by sending a crafted payload in an IP address input field. The vulnerability is related to insufficient input validation, allowing a remote attacker to execute arbitrary code using a specially crafted payload.
Recommendations For TP-Link TL-WR840N version 0.9.1 3.16 and earlier, consider disabling the traceroute function until a patch is available to prevent potential exploitation. Restrict access to the router's IP address input field to minimize the risk of remote code execution. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04701
CVE-2019-15060

Produtos afetados

Tp-Link Tl-Wr840N