PT-2019-18390 · Tp Link · Tp-Link Tl-Wr1043Nd
Malfuzzer
·
Published
2019-06-19
·
Updated
2020-08-24
·
CVE-2019-6972
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-WR1043ND version V2
Description
An issue allows credentials to be easily decoded and cracked through brute-force, WordList, or Rainbow Table attacks. The credentials in the "Authorization" cookie are encoded with URL encoding and base64, making them easily decodable. The username is stored in cleartext, and the password is hashed with the MD5 algorithm after decoding the URL encoded string with base64.
Recommendations
For TP-Link TL-WR1043ND version V2, consider changing the password to a strong and unique one, and avoid using the same password across multiple devices. As a temporary workaround, restrict access to the device's web interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Inadequate Encryption Strength
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Wr1043Nd