Tp-link
Tp-link Tl-wdr4300 Firmware: vulnerabilidades y CVE
Tp-link Tl-wdr4300 Firmware tiene 7 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 2 figuran en el catálogo de explotación activa de CISA.
CVE7
Últimos 12 meses0
Críticas1
Explotadas activamente2
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2015-3035 | Alta (7.5) | 84% | ⚠ Explotación activa | 22 abr 2015 | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-50224 | Media (6.5) | 16% | ⚠ Explotación activa | 3 may 2024 | TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link… |
| CVE-2013-4654 | Crítica (9.8) | 2.7% | — | 13 nov 2019 | Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND.. |
| CVE-2013-4848 | Alta (8.8) | 1.1% | — | 25 oct 2019 | TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities. |
| CVE-2019-6487 | Alta (8.8) | 8.5% | — | 18 ene 2019 | TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather… |
| CVE-2015-3035 | Alta (7.5) | 84% | ⚠ Explotación activa | 22 abr 2015 | Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600… |
| CVE-2014-4728 | Media (5) | 1.8% | — | 30 sept 2014 | The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request. |
| CVE-2014-4727 | Media (4.3) | 2.0% | — | 30 sept 2014 | Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.