CVE-2018-3951
01.12.2018, 06:29
An exploitable remote code execution vulnerability exists in the HTTP header-parsing function of the TP-Link TL-R600VPN HTTP Server. A specially crafted HTTP request can cause a buffer overflow, resulting in remote code execution on the device. An attacker can send an authenticated HTTP request to trigger this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
tp-link | tl-r600vpn_firmware | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration