vendor:
TL-WR1043ND V2
by:
Uriel Kosayev
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: TL-WR1043ND V2
Affected Version From: TL-WR1043ND V2
Affected Version To: TL-WR1043ND V2
Patch Exists: YES
Related CWE: CVE-2019-6971
CPE: h:tp-link:tl-wr1043nd_v2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: TL-WR1043ND V2
2019
TP-Link TL-WR1043ND 2 – Authentication Bypass
A vulnerability in TP-Link TL-WR1043ND V2 routers allows an attacker to bypass authentication and gain access to the router's web interface. This is due to the router's web interface not properly validating the Authorization header. An attacker can send a specially crafted HTTP request with a valid Authorization header to gain access to the router's web interface.
Mitigation:
Users should update their routers to the latest version available.