ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

"Classic" bugs open TP-Link's SafeStream Gigabit Broadband VPN Router to attack

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-3948
An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server.

An exploitable denial-of-service vulnerability exists in the URI-parsing functionality of the TP-Link TL-R600VPN HTTP server. A specially crafted URL can cause the server to stop responding to requests, resulting in downtime for the management portal. An attacker can send either an unauthenticated or authenticated web request to trigger this vulnerability.

NVD description · AI analysis pending
7.523% PoC
  • tp-link tl-r600vpn firmware
CVE-2018-3950
+2 in the same advisory: …3949 …3951
An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VPN HWv3 FRNv1.3.0 and HWv2 FRNv1.2.3 http

An exploitable remote code execution vulnerability exists in the ping and tracert functionality of the TP-Link TL-R600VPN HWv3 FRNv1.3.0 and HWv2 FRNv1.2.3 http server. A specially crafted IP address can cause a stack overflow, resulting in remote code execution. An attacker can send a single authenticated HTTP request to trigger this vulnerability.

NVD description · AI analysis pending
8.8
group max
3% PoC
  • tp-link tl-r600vpn firmware
Full article282 words · extracted from helpnetsecurity.com · click to collapse

Cisco Talos researchers have flagged four serious vulnerabilities in TP-Link’s SafeStream Gigabit Broadband VPN Router (TL-R600VPN). All four affect the device’s HTTP server, and can lead to denial of service, information disclosure, and remote code execution.

TL-R600VPN vulnerabilities

About the vulnerabilities

The flaws affect TP-Link TL-R600VPN, hardware versions 2 and 3.

Numbered CVE-2018-3948 and CVE-2018-3949, respectively, the flaws that can be exploited for DoS and information disclosure can be triggered via an unauthenticated web request and a specially crafted URL.

Both of the RCE flaws – CVE-2018-3950 and CVE-2018-3951 – can only be exploited within an authenticated session, meaning that the attacker must be logged in and malware has to be able to use the correct credentials to mount a successful attack.

Unfortunately for the world at large, many users never change the device’s login credentials, which are usually the same for all devices from the same product line. This fact is often misused by attackers looking for devices to rope into their botnets, and is a problem that some of the recently signed legislation is trying to solve.

“These are just the latest example that these pieces of equipment are not only vulnerable, they also lack the generic operating systems protections that mitigate vulnerabilities like buffer overflows,” the researchers pointed out. “Fortunately in the case of TL-R600VPN routers, the critical vulnerabilities that lead remote code execution need authentication. However, the code could be executed with root privileges.”spe

With all that in mind, and the fact that the researchers have detailed the flaws extensively and provided proof-of-concept exploit code, administrators of these devices would do well to download and implement the firmware updates provided by the manufacturer to plug these holes.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/11/20/tl-r600vpn-vulnerabilities/