PT-2019-9223 · Tp Link · Tp-Link Wr1043N
Publicado
2019-06-20
·
Atualizado
2020-08-24
·
CVE-2018-16119
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link WR1043nd version 3
Description
The issue is a stack-based buffer overflow in the httpd server, allowing remote attackers to execute arbitrary code via a malicious MediaServer request to "/userRpm/MediaServerFoldersCfgRpm.htm".
Recommendations
For TP-Link WR1043nd version 3, consider disabling access to the "/userRpm/MediaServerFoldersCfgRpm.htm" endpoint until a patch is available. Restrict access to the MediaServer functionality to minimize the risk of exploitation.
Exploit
Correção
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Tp-Link Wr1043N