Tenable Research Advisory: Popular TP-Link Router is Vulnerable to Remote Exploitation

Satnam Narang

Tenable Research has discovered multiple vulnerabilities in the TP-Link TL-WRN841N, a popular consumer router, one of which could be used by an attacker to remotely take over the device.

  • What do you need to know? Multiple vulnerabilities in TP-Link's popular TL-WRN841N router were discovered by Tenable Research.
  • What’s the attack vector? Targeting unauthenticated users of the TL-WRN841N router’s web server.
  • What’s the business impact? An attacker can obtain full control over the router, uploading a new configuration file that will change the admin credentials as well as enable remote access to control the device remotely.
  • What’s the solution? TP-Link plans to release a patch that will address these vulnerabilities.

Background

Tenable Researcher David Wells discovered multiple vulnerabilities in the TP-Link TL-WRN841N, a popular wireless router which boasts an average rating of four stars on Amazon with more than 12,000 reviews.

Analysis

The first vulnerability in the TL-WRN841N is an improper authentication flaw, which we discovered independently during our research. It was also reported to TP-Link at the same time by a third-party researcher. It received a CVE identifier of CVE-2018-11714. This vulnerability is local, as it would allow unauthenticated attackers to trigger a set of sensitive CGI routines in the router’s admin webpage by spoofing the HTTP Referrer request from "tplinkwifi.net," "tplinklogin.net" or the router's IP address.

Our research led us to discover a second vulnerability, a cross-site request forgery (CSRF) flaw in the HTTP referrer whitelist check function in the router’s httpd service. It received a CVE identifier of CVE-2018-15702. It uses a string comparison function, strncmp, which checks to see whether or not the URL contained in the HTTP referrer field matches one of the whitelisted domains. However, this check is performed in such a way that it only looks at a certain length of characters within the string. Therefore, an attacker could craft a malicious iframe pointing to a URL with the subdomain "tplinkwifi.net" or "tplinklogin.net" (e.g. hxxp://tplinkwifi.net.drive-by-attack[.]com) and the router would consider it part of its whitelisted domains. This CSRF, combined with the improper authentication vulnerability, could allow an attacker to obtain full control over the router by uploading a malicious configuration file that would overwrite the admin credentials and even enable access to the router’s remote administration interface.

Additionally, we discovered two local/unauthenticated denial of service (DoS) vulnerabilities, both of which can cause the httpd service to crash by sending a malformed HTTP request, requiring the router to be restarted.

Proof of Concept

The researcher who discovered these has also developed a proof of concept of the CSRF vulnerability.

Solution

As of this publication, a patch for these vulnerabilities has not been released. Tenable Research has been communicating and working with TP-Link to ensure these vulnerabilities are addressed in an upcoming firmware update. Impacted end-users can contact the vendor directly for further information. We will update this blog with a link to the vendor’s patch when it is made available.

Identifying Affected Systems

Tenable has the following plugins available for identifying vulnerable assets.

Plugin ID

Description

117861

TP-Link Unauthenticated CGI Cross-Site Request Forgery (remote check)

117860

TP-Link HTTP Server Detection

Additional information:

Learn more about Tenable.io, the first Cyber Exposure platform for holistic management of your modern attack surface. Get a free 60-day trial of Tenable.io Vulnerability Management.

Read more >

Published on Oct 2, 2018

People also viewed

API Delivery Engineer

Uxbridge United Kingdom Furzeground Way , Stockley Park, Uxbridge, United Kingdom, UB11 1EZ Professional Services Professional Services
Your Role:Assist in the deployment and configuration of Tenable solutions within client organisations. The consultant will provide technical support, preparation and documentation to clients as part of a small delivery team. The consultant will in...

Principal Research Engineer

Paris Paris France Paris, France Sensors Research & Development
Your Opportunity:As the Cyber Exposure market leader Tenable is looking for a passionate and talented Principal Researcher for its Tenable Research team. Tenable Research is significant and growing global security research team consisting of rever...

Security Consultant - API

North Sydney Australia Pacific Highway, North Sydney, Australia, NSW 2060 Professional Services Professional Services
Your Role:Tenable’s Global Professional Services organization performs Tenable product installation, configuration, customizations, and security audits for our clients, and is looking to hire a security consultant with expertise developing scripts...

Field Product Manager

Seattle Washington United States 5th Ave, Seattle, Washington, United States, 98101 Product Management Research & Development
Your Role:The Field Product Manager  supports and works with Product Management, Engineering, Product Marketing, Sales, and other internal teams to guide on how Tenable products and services could be used to best suit customer needs. This supporti...

Technical Product Manager - Cloud Services

New York New York United States Broadway, New York, United States, 10012 Product Management Research & Development
Your Role:Tenable is looking for a Technical Product Manager - Cloud Services, responsible for driving the product strategy and management of our cloud services, platform infrastructure, and public APIs. This full-stack PMrole is expected to be sk...

Sr. UI Engineer

Los Angeles California United States West Jefferson Boulevard, Playa Vista, Los Angeles, California, United States, 90066 Cloud Platforms Research & Development
Your Role:Tenable is looking for an extraordinary Senior UI Engineer to join the Tenable.io Engineering team. This is an opportunity to make a high impact while helping the team deliver on a next-generation enterprise web application. The ideal ca...

We have big plans for continued global growth, and we’re looking for people who are creative, flexible and dedicated to helping us build something great – something that matters.