github.com
https://github.com/MalFuzzer/Vulnerability-Research/blob/master/TL-WR1043ND%20V2%20-%20TP-LINK/TL-WR1043ND_PoC.pdf CVE-2019-6971
CRITICAL
TP-Link TL-WR1043ND 2 - Authentication Bypass
Record summary
CVE-2019-6971 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBTP-Link TL-WR1043ND 2 - Authentication BypassExploitDB exploitby Uriel KosayevNot analyzed1 file
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-6971 twitter.com
https://twitter.com/MalFuzzer/status/1141269335685652480?s=19