This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ated_tp service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link TL-WR841ND Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-17356 is high due to its potential to allow arbitrary code execution.
To fix ZDI-CAN-17356, update your TP-Link TL-WR841N router to the latest firmware provided by TP-Link.
ZDI-CAN-17356 affects installations of TP-Link TL-WR841N routers that have not applied the latest security updates.
ZDI-CAN-17356 cannot be exploited remotely as it requires network-adjacent access but the existing authentication can be bypassed.
Exploitation of ZDI-CAN-17356 could lead to unauthorized access and control over the affected TP-Link TL-WR841N routers.