Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-c5g7-7w25-772m

Опубликовано: 18 фев. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication.

A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication.

9.8 Critical

CVSS3

Дефекты

CWE-287

Связанные уязвимости

nvd
12 месяцев назад

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-11714. Reason: This candidate is a reservation duplicate of CVE-2018-11714. Notes: All CVE users should reference CVE-2018-11714 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.

CVSS3: 9.8
fstec
12 месяцев назад

Уязвимость микропрограммного обеспечения маршрутизаторов TP-Link TL-WR840N, связанная с недостатками процедуры аутентификации, позволяющая нарушителю обойти существующие ограничения безопасности

9.8 Critical

CVSS3

Дефекты

CWE-287