Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
http://tp-link.com/ | vendor advisory |
https://www.secsignal.org/news/exploiting-routers-just-another-tp-link-0day | third party advisory exploit |