Release date: 2013-03-11
Updated on: 2013-03-13
Affected Systems:
TP-LINK TL-WDR4300 TL-WR743ND (v1.2)
TP-LINK TL-WDR4300 TL-WDR4300
Description:
--------------------------------------------------------------------------------
TP-Link is a popular wireless router.
Some wireless router devices of TP-Link have backdoors. By sending specific requests, you can completely control the devices.
Send the "http: // 192.168.0.1/userRpmNatDebugRpm26525557/start_art.html" request to the device (assuming the IP address of the router is 192.168.0.1). The router downloads an nart from the machine that initiates the request. and run the file as root.
<* Source: sekurak
Michal Sajdak (michal. sajdak [at] securitum. pl)
Link: http://sekurak.pl/tp-link-httptftp-backdoor/
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
TP-LINK
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.tp-link.com/products/