TL-MR100 V3.20 中的 函数存在一个预认证(pre-authentication)堆栈缓冲溢出漏洞,原因是针对 端点的加密请求缺乏足够的边界检查。能够访问路由器 Web 管理界面的未认证相邻攻击者可以触发内存损坏,并有可能实现任意代码执行。 成功利用该漏洞可在认证之前覆盖 进程堆栈上保存的控制流数据,从而导致服务崩溃或在受影响进程的上下文中实现任意代码执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | TL-MR100 v3.20 | 0 ~ (EU)_1.3.0 Build 260609 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet