[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

TP-LINK Model No. TL-WR340G / TL-WR340GD - Multiple Vulnerabilities

[ 0Day-ID-22397 ]
Full title
TP-LINK Model No. TL-WR340G / TL-WR340GD - Multiple Vulnerabilities [ Highlight ]
Highlight - is paid service, that can help to get more visitors to your material.

Price: 10
Date add
Category
Platform
Verified
Price
free
Risk
[
Security Risk High
]
Rel. releases
Description
TP-LINK Model No. TL-WR340G & TL-WR340GD suffers on multiple persistent cross site scripting and cross site request forgery vulnerabilities.

Persistent Cross Site Scripting vulnerabilities exists because of poor parameters filtration. Our value is stored in javascript array, since it's not correctly verified nor filtered, it is able to inject javascript code. It will be executed whenever user will visit specific settings page. Because of no CSRF prevention, it is able to compromise router. Attacker may force user to restore factory default settings, and then to turn on remote managment; in result, it will be able to log in using default username and password credentials(admin:admin).
Vendor
tplink.com
Affected ver
TL-WR340G & TL-WR340GD
Tested on
Firmware Version - 4.3.7 Build 090901 Rel.61899n, Hardware Version - WR340G v5 081520C2 [at] Linux
Solution
CSRF prevention mechanism and solid parameters filtration.
Tags
Other Information
Abuses
0
Comments
0
Views
4 839
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
free
Open Exploit
You can open this source code for free
Open Exploit
Open Exploit
You can open this source code for free
Author
BL
29
Exploits
32
Readers
1
[ Comments: 0 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.

Login or register to leave comments