TP-LINK TL-WR2543ND Cross-Site Request Forgery Vulnerability
Release date:
Updated on:
Affected Systems:
TP-LINK TL-WR2543ND 3.13.6 build 110923 Rel.53137n
Description:
--------------------------------------------------------------------------------
TP-LINK TL-WR2543ND is a wireless router product.
The TP-LINK TL-WR2543ND has a Cross-Site Request Forgery Attack Vulnerability in firmware 3.13.6 build 110923 Rel.53137n that allows users to perform certain operations through unauthenticated HTTP requests, for example, when a logged-on administrator browses a special webpage, attackers can exploit this vulnerability to create an FTP user or disable the status detection firewall of the router.
<* Source: Juan Manuel Garcia
Link: http://secunia.com/advisories/52070/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TP-LINK
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.tp-link.com/products/