CVE-2018-16119
HIGHTP-Link TL-WR1043ND Firmware Version 3 - Remote Code Execution via MediaServer Request
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2018-16119. PoCs published by hdbreaker.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2018-16119, an authenticated remote code execution vulnerability in TP-Link TL-WR1043ND routers. The exploit leverages a stack overflow to execute arbitrary commands with root privileges via a reverse shell.
Description
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.
Exploits (1)
This repository contains a functional exploit for CVE-2018-16119, an authenticated remote code execution vulnerability in TP-Link TL-WR1043ND routers. The exploit leverages a stack overflow to execute arbitrary commands with root privileges via a reverse shell.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H