First published: Tue Sep 30 2014(Updated: )
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tp-link Tl-wr841n Firmware | <=3.13.9 | |
TP-LINK TL-WR841N |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-6316 is classified as a high severity vulnerability due to its potential for remote code execution through cross-site scripting.
To fix CVE-2012-6316, update the TP-LINK TL-WR841N router firmware to a version later than 3.13.9.
CVE-2012-6316 affects the TP-LINK TL-WR841N router with firmware versions 3.13.9 and earlier.
CVE-2012-6316 is a cross-site scripting (XSS) vulnerability that allows attackers to inject malicious scripts.
Yes, CVE-2012-6316 can be exploited remotely by manipulating the username or password fields in the router's web interface.