TP-LINK WDR4300 Web Server Denial of Service Vulnerability


Description   A vulnerability has been reported in TP-LINK WDR4300 Router, which can be exploited by malicious people to cause a DoS (Denial of Service).
The vulnerability is caused due to an error in the web server component when parsing overly long GET requests and can be exploited to cause a crash.
The vulnerability is reported in firmware versions prior to 1.140916.
     
Vulnerable Products   Vulnerable OS:
TP-LINK TL-WDR4300 RouterVulnerable Software:
     
Solution   Update to firmware version 1.140916.
     
CVE   CVE-2014-4728
     
References   http://packetstormsecurity.com/files/128343/TP-LINK-WDR4300-XSS-Denial-Of-Service.html
     
Vulnerability Manager Detection   No
     
IPS Protection  
ASQ Engine alarm Available Since
Possible buffer overflow in HTTP request/reply
3.2.0
     


 
 
 
 
 Risk level 
Low 

 Vulnerability First Public Report Date 
2014-10-22 

 Target Type 
Server 

 Possible exploit 
Remote