Advisory

TP-Link TL-WR840N Configuration Import Cross-Site Request Forgery (CSRF)

Dell SecureWorks Security Advisory SWRX-2015-001

Advisory Information

  • Title: TP-Link TL-WR840N Configuration Import Cross-Site Request Forgery (CSRF)
  • Advisory ID: SWRX-2015-001
  • Date published: Wednesday, January 7, 2015
  • CVE: CVE-2014-9510
  • CVSS v2 base score: 9.3
  • Date of last update: Wednesday, January 7, 2015
  • Vendors contacted: TP-Link
  • Release mode: Coordinated
  • Discovered by: Sean Wright, Dell SecureWorks

Summary

TP-Link is a primary provider of networking equipment and wireless products for small and home offices as well as for small to midsized businesses. TL-WR840N is a combination wired/wireless router specifically targeted to small business and home office networking environments. The router's web administration console contains a cross-site request forgery (CSRF) vulnerability that allows threat actors to import their own configuration to the router. An attack could alter any configuration setting on the device.

Download the PDF: SWRX-2015-001

PGP Signature


ABOUT THE AUTHOR
カウンター・スレット・ユニット・リサーチチーム

The Secureworks Counter Threat Unit™ (CTU) is a dedicated threat research team that analyzes threat data across our global customer base and actively monitors the threat landscape.
ブログ記事一覧ページに戻る

今すぐ Taegis を試す

ご確認ください。 Taegis がどのようにリスクを軽減し、既存のセキュリティ投資を最適化し、人材不足を解消ことができるかをデモでご覧ください。