vendor:
TP-Link TL-WR940N
by:
Amirhossein Bahramizadeh
9.9
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: TP-Link TL-WR940N
Affected Version From: TP-Link TL-WR940N V4
Affected Version To: TP-Link TL-WR940N V4
Patch Exists: NO
Related CWE: CVE-2023-36355
CPE: o:tp-link:tl-wr940n_firmware
Platforms Tested: Windows, Linux
2023
TP-Link TL-WR940N V4 – Buffer OverFlow
This exploit triggers a buffer overflow vulnerability in TP-Link TL-WR940N V4 routers. By sending a crafted payload to the vulnerable endpoint, an attacker can cause a buffer overflow, potentially leading to remote code execution or denial of service. The vulnerability is identified by CVE-2023-36355.
Mitigation:
To mitigate this vulnerability, it is recommended to update the firmware of the TP-Link TL-WR940N V4 router to the latest version provided by the vendor. Additionally, it is advised to restrict access to the router's administration interface only to trusted networks and regularly monitor for any unusual activity.