« Volver al listado

CVE-2014-9350

Estado: ModificadaMedia (5)—

TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2014-9350",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2014-12-08T16:59:22.370",
  "references": [
    {
      "url": "http://packetstormsecurity.com/files/129227/TP-Link-TL-WR740N-Denial-Of-Service.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.exploit-db.com/exploits/35345",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/115017",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5210.php",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98927",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://packetstormsecurity.com/files/129227/TP-Link-TL-WR740N-Denial-Of-Service.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.exploit-db.com/exploits/35345",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/115017",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zeroscience.mk/en/vulnerabilities/ZSL-2014-5210.php",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/98927",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-19"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a \"new\" value in the isNew parameter to PingIframeRpm.htm."
    },
    {
      "lang": "es",
      "value": "TP-Link TL-WR740N 4 con firmware 3.17.0 Build 140520, 3.16.6 Build 130529, y 3.16.4 Build 130205 permite a atacantes remotos causar una denegación de servicio (caída de httpd) a través de vectores que involucran un valor 'nuevo' en el parámetro isNew en PingIframeRpm.htm."
    }
  ],
  "lastModified": "2026-06-17T00:18:08.967",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:tp-link:tl-wr740n_firmware:3.16.4:130205:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "28A738A7-3B22-4921-A872-E24B42389586"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tl-wr740n_firmware:3.16.6:130529:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "88C725FB-4E2D-42D4-939A-526F23702EF2"
            },
            {
              "criteria": "cpe:2.3:o:tp-link:tl-wr740n_firmware:3.17.0:140520:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E6331F1-2CD6-4FBD-AFB6-963D7891EE7B"
            }
          ],
          "operator": "OR"
        },
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:h:tp-link:tl-wr740n:4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "530FA9E7-C40E-4327-9FDD-F49944E9D658"
            }
          ],
          "operator": "OR"
        }
      ],
      "operator": "AND"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}