Vulnerability detection on TP-Link routers allows an attacker to log in without a password
TP-Link has just announced the successful development of a patch for a serious security hole affecting some Archer routers, which could allow potential attackers to control devices through Remote LAN via Telnet connection without having to provide administrator password.
'In the case of a successful exploit, this vulnerability could allow a remote attacker to control the configuration of the router via Telnet on the local area network (LAN) and connect to the FTP server via LAN or WAN ', said security expert Grzegorz Wypych of the IBM X-Force Red team.
To exploit this security vulnerability, an attacker must send an HTTP request that contains a string longer than the number of bytes allowed, resulting in the user password being completely disabled and replaced with a value. hollow.
The built-in authentication is completely 'useless' in this case because it only checks the referrer's HTTP headers, allowing the attacker to mislead the httpd router service that this request is valid by Use hard-coded tplinkwifi.net value.
The users of these routers are mainly system administrators, who have full root access, so once the threat actors can bypass the authentication process, they will automatically gain administrative privileges. administrator on the router. After that, all processes will be run by this access holder. As such, it can be said that the attacker acted as an administrator and successfully hijacked the device.
"Attackers not only can gain high-level access, but legitimate users will also be blocked and no longer be able to log in to the web service through the regular user interface, resulting in no unable to reset new password ', added Mr. Grzegorz Wypych.
Worse, even if the router owner sets a new password, an attacker can continue to disable it with a LAN / WAN / CGI request, causing the USB connection to the built-in FTP server to become The only way to access the router. In addition, RSA encryption keys will not be applicable in this case because they do not work with blank passwords.
This vulnerability is being monitored with the identifier CVE-2019-7405, affecting Archer C5 V4, Archer MR200v4, Archer MR6400v4 and Archer MR400v3 routers. TP-Link has released patches to help customers protect their routers from related attacks. As follows:
TP-Link routers are affected by Archer C5 V4 security patchhttps://static.tp-link.com/2019/201909/20190917/Archer_C5v4190815.rarArcher MR200v4https://static.tp-link.com/2019/201909/20190903/Archer%20MR200(EU)_V4_20190730.zipArcher MR6400v4https://static.tp-link.com/2019/201908/20190826/Archer%20MR6400(EU)_V4_20190730.zipArcher MR400v3https://static.tp-link.com/2019/201908/20190826/Archer % 20MR400 (EU) _V3_20190730.zip
You should read it
- Review TP-Link Archer C50: Cheap router with attractive design
- TP-Link Archer AX6000 review: lightning fast WiFi router
- Top 5 best TP-Link routers today
- TP-Link Archer C7 (AC1750) Review: Excellent Cheap Dual Band Gigabit Router
- 10 best VPN routers 2020
- Guide DTCL Gunner lineup 2
- How to change WiFi Archer C9 password, replace pass WiFi TP Link Archer C9 simple
- Top best 802.11ac Wi-Fi wireless router
May be interested
- Review of TP-LINK Archer C5 routertp-link archer c5 is an old and classic wireless router, popular in the market of affordable routers. its success convinced the company to create a new version of this model, the tp-link archer c5 v4.
- Critical RCE vulnerability affects 29 DrayTek router modelsresearchers from security firm trellix have discovered an unauthenticated remote code execution (rce) vulnerability affecting 29 models of draytek routers.
- How to create and add TP-Link ID to TP-Link WiFi 6 routertp-link id is a cloud-based account that you can use on all tp-link wifi 6 routers, wifi mesh systems and smart home devices.
- Instructions on how to change the TP-Link Wifi passwordchanging wifi password regularly will help protect your internet better, avoid the case of neighbors using the temple. i will guide you how to change the wifi password on tp-link modem. you open the browser on your computer or phone and access
- Detecting WhatsApp flaws allows an attacker to access files on the machinethis is a cross-site scripting (xss) vulnerability.
- The best gaming routers todaytop gaming routers are designed to prioritize network traffic from games, through a feature called quality of service - quality of service (qos), so your gaming will not interrupted if the roommate is trying to watch netflix at the same time. here are the best gaming routers you can buy at the present time.
- Good hackers find and patch the vulnerability for more than 100,000 other routersrecently, zdnet has reported on a white hat hacker claiming to be alexey, specializing in finding vulnerabilities in mikrotik router system and patching up so that bad guys can't use them to do bad things.
- The best Travel Router you need to bring in your triptravel routers are often considered the 'swiss army knife' of the internet. this small device is no bigger than a credit card but don't let its small physique fool you.
- How to change Wifi password, change wifi pass VNPT, FPT, Tenda, TP-Link, Viettel on computer, phonechanging this wifi password will make it easier to change wifi passwords, increase wifi security. here is a summary of how to change wifi pass for the most popular modems, such as: fpt, tenda, tp-link, viettel, please refer.
- How to enable the leaked Chrome password featurethe password leak detection feature on chrome will detect if the saved password has been leaked or not.