CVE-2017-13772
HIGHTP-Link WR940N Hardware v4 - Authenticated Remote Code Execution via PingIframeRpm.htm or WanStaticIpV6CfgRpm.htm
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2017-13772. PoCs published by Patrik Lantz, Fidus InfoSecurity.
AI-analyzed exploit summary This exploit leverages a stack-based buffer overflow in TP-Link WDR4300 routers (CVE-2017-13772) to achieve remote code execution. It includes MIPS shellcode for a reverse TCP shell, requires authentication, and targets specific firmware versions.
Description
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.
Exploits (2)
This exploit leverages a stack-based buffer overflow in TP-Link WDR4300 routers (CVE-2017-13772) to achieve remote code execution. It includes MIPS shellcode for a reverse TCP shell, requires authentication, and targets specific firmware versions.
This exploit targets CVE-2017-13772, an authenticated remote code execution vulnerability in TP-Link WR940N routers. It uses a bind shell payload (port 31337) and leverages a stack-based buffer overflow via crafted parameters in the router's web interface.
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H