CVE-2017-13772: Buffer Overflow
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) pingaddr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-13772?
CVE-2017-13772 is classified as critical due to its potential for remote code execution.
How do I fix CVE-2017-13772?
To fix CVE-2017-13772, update the firmware of the TP-Link WR940N WiFi router to the latest version provided by the manufacturer.
Who is affected by CVE-2017-13772?
CVE-2017-13772 affects TP-Link WR940N WiFi routers with hardware version 4 when running vulnerable firmware.
Can CVE-2017-13772 be exploited remotely?
Yes, CVE-2017-13772 can be exploited by remote authenticated users allowing them to execute arbitrary code.
What are the vulnerable parameters in CVE-2017-13772?
The vulnerable parameters in CVE-2017-13772 are ping_addr in PingIframeRpm.htm and dnsserver2 in WanStaticIpV6CfgRpm.htm.