Tl Wr1043nd Firmware
by TP-Link
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2019-6971 | Cri | 0.68 | 9.8 | 0.14 | Jun 19, 2019 | An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials. | ||
| CVE-2018-16119 | Hig | 0.50 | 7.2 | 0.34 | Jun 20, 2019 | Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm. | ||
| CVE-2013-2646 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2020 | TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability. | ||
| CVE-2019-6972 | Hig | 0.49 | 7.5 | 0.01 | Jun 19, 2019 | An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy… |
- risk 0.68cvss 9.8epss 0.14
An issue was discovered on TP-Link TL-WR1043ND V2 devices. An attacker can send a cookie in an HTTP authentication packet to the router management web interface, and fully control the router without knowledge of the credentials.
- risk 0.50cvss 7.2epss 0.34
Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.
- risk 0.49cvss 7.5epss 0.01
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
- risk 0.49cvss 7.5epss 0.01
An issue was discovered on TP-Link TL-WR1043ND V2 devices. The credentials can be easily decoded and cracked by brute-force, WordList, or Rainbow Table attacks. Specifically, credentials in the "Authorization" cookie are encoded with URL encoding and base64, leading to easy…