CVE-2019-17147
HIGHTP-LINK TL-WR841N Firmware - Unauthenticated Remote Code Execution via Host Header Buffer Overflow
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2019-17147. PoCs published by DrmnSamoLiu, imnot-ye.
AI-analyzed exploit summary This repository provides detailed instructions and firmware binaries for downgrading a TP-Link WR841N router to a vulnerable version to reproduce CVE-2019-17147. It includes technical steps for flashing partitions and debugging tools like busybox and gdbserver.
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.
Exploits (2)
This repository provides detailed instructions and firmware binaries for downgrading a TP-Link WR841N router to a vulnerable version to reproduce CVE-2019-17147. It includes technical steps for flashing partitions and debugging tools like busybox and gdbserver.
The repository contains firmware files and scripts from a vulnerable device, likely a router, associated with CVE-2019-17147. The files include configuration scripts and JavaScript files, but no explicit exploit code is present. The content appears to be extracted firmware for analysis rather than a functional exploit.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H