ID
VAR-201302-0512
TITLE
Multiple Cross-Site Request Forgery Vulnerabilities in TP-LINK TL-WR2543ND Management Panel
Trust: 0.6
DESCRIPTION
The TP-LINK TL-WR2543ND is a wireless router device. TP-LINK TL-WR2543ND has multiple cross-site request forgery vulnerabilities, which allows an attacker to exploit a vulnerability to construct a malicious URI, entice a user to resolve, and perform malicious operations in the target user context. TP-LINK TL-WR2543ND is prone to multiple cross-site request-forgery vulnerabilities because the application fails to properly validate HTTP requests. Exploiting these issues may allow a remote attacker to change a device's configuration and perform other unauthorized actions. TP-LINK TL-WR2543ND 3.13.6 Build 110923 is vulnerable; other versions may also be affected
Trust: 0.81
IOT TAXONOMY
| category: | ['Network device'] | sub_category: | - | Trust: 0.6 |
AFFECTED PRODUCTS
| vendor: | tp link | model: | tl-wr2543nd | scope: | - | version: | - | Trust: 0.6 |
| vendor: | tp link | model: | tl-wr2543nd build | scope: | eq | version: | 3.13.6110923 | Trust: 0.3 |
THREAT TYPE
remote
Trust: 0.6
TYPE
cross-site request forgery
Trust: 0.6
EXTERNAL IDS
| db: | BID | id: | 57877 | Trust: 1.5 |
| db: | CNVD | id: | CNVD-2013-01044 | Trust: 0.6 |
| db: | CNNVD | id: | CNNVD-201302-345 | Trust: 0.6 |
REFERENCES
| url: | http://www.securityfocus.com/bid/57877 | Trust: 1.2 |
| url: | http://packetstorm.foofus.com/1302-exploits/tplink-xsrf.pdf | Trust: 0.3 |
| url: | http://www.tp-link.com/us/products/details/?model=tl-wr2543nd | Trust: 0.3 |
| url: | http://www.tp-link.com/en/ | Trust: 0.3 |
CREDITS
Juan Manuel Garcia
Trust: 0.9
SOURCES
| db: | CNVD | id: | CNVD-2013-01044 |
| db: | BID | id: | 57877 |
| db: | CNNVD | id: | CNNVD-201302-345 |
LAST UPDATE DATE
2022-05-17T01:43:25.715000+00:00
SOURCES UPDATE DATE
| db: | CNVD | id: | CNVD-2013-01044 | date: | 2013-02-19T00:00:00 |
| db: | BID | id: | 57877 | date: | 2013-02-08T00:00:00 |
| db: | CNNVD | id: | CNNVD-201302-345 | date: | 2013-02-22T00:00:00 |
SOURCES RELEASE DATE
| db: | CNVD | id: | CNVD-2013-01044 | date: | 2013-02-19T00:00:00 |
| db: | BID | id: | 57877 | date: | 2013-02-08T00:00:00 |
| db: | CNNVD | id: | CNNVD-201302-345 | date: | 2013-02-22T00:00:00 |