In TP-LINK TL-WR741N / TL-WR741ND 150M Wireless Lite N Router with Firmware Version 3.11.7 Build 100603 Rel.56412n and Hardware Version: WR741N v1/v2 00000000, parameter SSID in the "Wireless Settings" is not properly validated. It's possible to inject malicious code: </script><H1>BUG/* </script><a href=XXX.com>. The second payload blocks the change of wireless settings. A factory reset is required.
References
Link | Resource |
---|---|
https://angeloanatrella86.github.io/CVE-2017/ | Exploit Issue Tracking Third Party Advisory |
Information
Published : 2017-10-31 11:29
Updated : 2017-11-22 09:06
NVD link : CVE-2017-14250
Mitre link : CVE-2017-14250
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
tp-link
- tl-wr741nd
- tl-wr741nd_firmware
- tl-wr741n
- tl-wr741n_firmware