PT-2018-10772 · Tp Link · Tp-Link Tl-Wr841N+1
Published
2018-06-04
·
Updated
2018-07-31
·
CVE-2018-11714
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-WR840N version 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n
TP-Link TL-WR841N version 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n
Description
The issue is caused by improper session handling on the "/cgi/" folder or a "/cgi" file. An attacker can exploit this by sending a header of "Referer: http://192.168.0.1/mainFrame.htm", which allows them to perform any action without requiring authentication.
Recommendations
For TP-Link TL-WR840N version 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n, restrict access to the /cgi/ folder to minimize the risk of exploitation.
For TP-Link TL-WR841N version 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n, avoid using the "/cgi/" folder until the issue is resolved.
Exploit
Fix
Session Fixation
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Wr840N
Tp-Link Tl-Wr841N