packetstormsecurity.com
http://packetstormsecurity.com/files/158999/TP-Link-WDR4300-Remote-Code-Execution.html CVE-2017-13772
HIGH
TP-Link WR940N - (Authenticated) Remote Code
Record summary
CVE-2017-13772 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.
Description
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 2
Proofs of concept
2Catalogued exploits
ExploitDBTP-Link WR940N - (Authenticated) Remote CodeExploitDB exploitby Fidus InfoSecurityNot analyzed1 file
ExploitDBTP-Link WDR4300 - Remote Code Execution (Authenticated)ExploitDB exploitby Patrik LantzNot analyzed1 file
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-13772 43022exploit
https://www.exploit-db.com/exploits/43022 fidusinfosec.com
https://www.fidusinfosec.com/tp-link-remote-code-execution-cve-2017-13772