Release date: 2012-03-12
Updated on: 2012-03-13
Affected Systems:
TP-LINK TL-WR740N
Description:
--------------------------------------------------------------------------------
Bugtraq id: 52424
TL-WR740N is a wireless router in TP-LINK's Mbps product line.
The TP-LINK TL-WR740N has an HTML injection vulnerability in implementation when it verifies the input of the "ping_addr" parameter passed to maintenance/tools_test.htm (Set "doType" to "ping, as a result, HTML or script code is run on the affected site to steal the Cookie authentication credential and control the website appearance.
<* Source: l20ot
Link: http://secunia.com/advisories/48357/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TP-LINK
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.tp-link.com/products/productDetails.asp? Pmodel = TL-WR740N