Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2013-4654

Disclosure Date: November 13, 2019 (last updated November 27, 2024)
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
Attacker Value
Unknown

CVE-2013-4848

Disclosure Date: October 25, 2019 (last updated November 27, 2024)
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
Attacker Value
Unknown

CVE-2019-6487

Disclosure Date: January 18, 2019 (last updated November 27, 2024)
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
0
Attacker Value
Unknown

CVE-2015-3035

Disclosure Date: April 22, 2015 (last updated July 17, 2024)
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
Attacker Value
Unknown

CVE-2014-4727

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.
0
Attacker Value
Unknown

CVE-2014-4728

Disclosure Date: September 30, 2014 (last updated October 05, 2023)
The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.
0