CVE-2017-13772

HIGH

TP-Link WR940N Hardware v4 - Authenticated Remote Code Execution via PingIframeRpm.htm or WanStaticIpV6CfgRpm.htm

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2017-13772. PoCs published by Patrik Lantz, Fidus InfoSecurity.

AI-analyzed exploit summary This exploit leverages a stack-based buffer overflow in TP-Link WDR4300 routers (CVE-2017-13772) to achieve remote code execution. It includes MIPS shellcode for a reverse TCP shell, requires authentication, and targets specific firmware versions.

Description

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.

Exploits (2)

exploitdb WORKING POC
by Patrik Lantz · pythonremotehardware
https://www.exploit-db.com/exploits/48994

This exploit leverages a stack-based buffer overflow in TP-Link WDR4300 routers (CVE-2017-13772) to achieve remote code execution. It includes MIPS shellcode for a reverse TCP shell, requires authentication, and targets specific firmware versions.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TP-Link WDR4300 (N750) with firmware 3.13.33 or 3.14.3
Auth required
Prerequisites: Default admin credentials · Network access to the router's web interface · Attacker-controlled IP for reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
by Fidus InfoSecurity · pythonwebappshardware
https://www.exploit-db.com/exploits/43022

This exploit targets CVE-2017-13772, an authenticated remote code execution vulnerability in TP-Link WR940N routers. It uses a bind shell payload (port 31337) and leverages a stack-based buffer overflow via crafted parameters in the router's web interface.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: TP-Link WR940N firmware (version not specified)
Auth required
Prerequisites: Network access to the router's web interface · Valid credentials (default: admin:admin)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/43022/

Scores

CVSS v3 8.8
EPSS 0.5256
EPSS Percentile 98.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-119
Status published
Products (1)
tp-link/wr940n_firmware
Published Oct 23, 2017
Tracked Since Feb 18, 2026