ID

VAR-E-201209-0574


TITLE

TP-LINK TL-WR340G Denial Of Service

Trust: 0.5

sources: PACKETSTORM: 116279

DESCRIPTION

The TP-LINK TL-WR340G SOHO router version 4.7.11 suffers from a malformed packet denial of service vulnerability.

Trust: 0.5

sources: PACKETSTORM: 116279

AFFECTED PRODUCTS

vendor:tp linkmodel:tl-wr340gscope: - version: -

Trust: 0.5

sources: PACKETSTORM: 116279

EXPLOIT

=== intro ===

TP-LINK TL-WR340G is a SOHO router with integrated IEEE 802.11b/g AP.
Now it's marked End-of-Life.

Transmitting crafted frames in proximity of working router cause device
to malfunction. Wireless communication stops, existing clients don't
receive frames from AP ( except beacons ), new clients can't connect.

=== details ===

Affected product: TL-WR340G Wireless router
Firm Version: 4.7.11 Build 101102 Rel.60376n
Hardware Version: WR340G v3
Local/remote: Local ( wirelessly )

Vulnerability can be spotted by crafting and transmitting frame with scapy:

>> fr = RadioTap()/Dot11(addr1="ff:ff:ff:ff:ff:ff",addr2="<AP
MAC>",addr3="<AP MAC>")/Dot11Beacon()/Dot11Elt()
>> sendp(fr,iface="injection capable wireless interface",count=5)

Attacker could cease wireless traffic. To resume AP functionality user
must restart wireless interface in WebGUI or restart device.

=== time-line ===
2.08.2012 - vendor notified
4.09.2012 - no response from vendor, published

Trust: 0.5

sources: PACKETSTORM: 116279

EXPLOIT HASH

LOCAL

SOURCE

md5: 892310cfb5f652fe26593493ac94b5ea
sha-1: 25af0c693a11c3f66bc0a3f7839cd0a940fa952d
sha-256: f2ab91cefb5d3c34ef3c5f25631dee0fbc99006715f4802a13aa94c5acc61698
md5: 892310cfb5f652fe26593493ac94b5ea

Trust: 0.5

sources: PACKETSTORM: 116279

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 116279

TAGS

tag:exploit

Trust: 0.5

tag:denial of service

Trust: 0.5

sources: PACKETSTORM: 116279

CREDITS

Adam P.

Trust: 0.5

sources: PACKETSTORM: 116279

EXTERNAL IDS

db:PACKETSTORMid:116279

Trust: 0.5

sources: PACKETSTORM: 116279

SOURCES

db:PACKETSTORMid:116279

LAST UPDATE DATE

2022-07-27T09:19:01.394000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:116279date:2012-09-06T20:22:22