TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
BID:46738
Info
TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
| Bugtraq ID: | 46738 |
| Class: | Unknown |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2011 12:00AM |
| Updated: | Mar 04 2011 12:00AM |
| Credit: | Ewerson Guimaraes aka Crash. DcLabs Security Research Group |
| Vulnerable: |
TP-LINK TL-WR740N 3.12.4 Build 100910. TP-LINK TL-WR740N 3.11.7 Build 100603. |
| Not Vulnerable: | |
Discussion
TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
TP-LINK TL-WR740N router is prone an HTML-injection vulnerability and a denial-of-service vulnerability.
Exploiting the HTML-injection issue may allow an attacker to execute HTML and script code in the context of the device, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Attackers can exploit the denial-of-service issue to make the affected device unresponsive, resulting in a denial-of-service condition.
TL-WR740N 3.12.4 Build 100910 Rel.57694n and 3.11.7 Build 100603 Rel.56412n versions are vulnerable; other versions may also be affected.
TP-LINK TL-WR740N router is prone an HTML-injection vulnerability and a denial-of-service vulnerability.
Exploiting the HTML-injection issue may allow an attacker to execute HTML and script code in the context of the device, to steal cookie-based authentication credentials, or to control how the site is rendered to the user; other attacks are also possible.
Attackers can exploit the denial-of-service issue to make the affected device unresponsive, resulting in a denial-of-service condition.
TL-WR740N 3.12.4 Build 100910 Rel.57694n and 3.11.7 Build 100603 Rel.56412n versions are vulnerable; other versions may also be affected.
Exploit / POC
TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
Attackers can exploit these issues with readily available tools.
Attackers can exploit these issues with readily available tools.
Solution / Fix
TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
TP-LINK TL-WR740N Router HTML Injection and Denial of Service Vulnerabilities
References:
References:
- TL-WR740N Router (TP-LINK)
- [DCA-2011-0001] TP-LINK TL-WR740N Multiple Vulnerabilities - Stored XSS - Web Co (Ewerson Guimarães (Crash) - Dclabs)