TP Link MR200 V4 Firmware version 210201 was discovered to contain a null-pointer-dereference in the web administration panel on /cgi/login via the sign, Action or LoginStatus query parameters which could lead to a denial of service by a local or remote unauthenticated attacker.
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://lenoctambule.dev/post/dos-on-tp-link-web-admin-panel | third party advisory exploit |