CVE-2018-3948
Summary
| CVE | CVE-2018-3948 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-11-30 17:29:00 UTC |
| Updated | 2023-02-03 18:29:00 UTC |
| Description | An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in downtime for the management portal. An attacker can send either an unauthenticated or authenticated web request to trigger this vulnerability. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Tp-link | Tl-r600vpn | v2 | All | All | All |
| Hardware | Tp-link | Tl-r600vpn | v3 | All | All | All |
| Hardware | Tp-link | Tl-r600vpn | v2 | All | All | All |
| Hardware | Tp-link | Tl-r600vpn | v3 | All | All | All |
| Operating System | Tp-link | Tl-r600vpn Firmware | 1.2.3 | All | All | All |
| Operating System | Tp-link | Tl-r600vpn Firmware | 1.3.0 | All | All | All |
| Operating System | Tp-link | Tl-r600vpn Firmware | 1.2.3 | All | All | All |
| Operating System | Tp-link | Tl-r600vpn Firmware | 1.3.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| TALOS-2018-0617 || Cisco Talos Intelligence Group - Comprehensive Threat Intelligence | MISC | talosintelligence.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.