First published: Mon Dec 08 2014(Updated: )
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tp-link Tl-wr740n Firmware | =3.16.4-130205 | |
Tp-link Tl-wr740n Firmware | =3.16.6-130529 | |
Tp-link Tl-wr740n Firmware | =3.17.0-140520 | |
TP-Link TL-WR740N V6 | =4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-9350 has a moderate severity level as it can cause a denial of service by crashing the HTTP server.
To fix CVE-2014-9350, you should upgrade the firmware of the TP-Link TL-WR740N to a more recent version that addresses this vulnerability.
CVE-2014-9350 affects the TP-Link TL-WR740N devices running firmware versions 3.16.4 Build 130205, 3.16.6 Build 130529, and 3.17.0 Build 140520.
CVE-2014-9350 enables remote attackers to perform a denial of service attack that crashes the HTTP server on the device.
While upgrading the firmware is the best solution for CVE-2014-9350, limiting external access to the device may serve as a temporary workaround.