Record summary

CVE-2017-13772 has a selected CVSS score of 8.8 (high); EIP currently links 2 catalogued exploits.

Description

Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
2

Proofs of concept

2

Catalogued exploits

ExploitDBTP-Link WR940N - (Authenticated) Remote CodeExploitDB exploitby Fidus InfoSecurityNot analyzed1 file
ExploitDB

PoC details
ExploitDBTP-Link WDR4300 - Remote Code Execution (Authenticated)ExploitDB exploitby Patrik LantzNot analyzed1 file
ExploitDB

PoC details

References

4