Skip to content

Commit 5775d51

Browse files
authored
updated matcher
1 parent e8988e0 commit 5775d51

File tree

1 file changed

+4
-1
lines changed

1 file changed

+4
-1
lines changed

http/cves/2024/CVE-2024-57050.yaml

+4-1
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,14 @@
11
id: CVE-2024-57050
22

33
info:
4-
name: TP-LINK WR840N v6 up to 0.9.1 4.16 /cgi Improper Authentication
4+
name: TP-LINK WR840N v6 up to 0.9.1 4.16 - Improper Authentication
55
author: DhiyaneshDK
66
severity: critical
77
description: |
88
A vulnerability in the TP-Link WR840N v6 router with firmware version 0.9.1 4.16 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory.When adding Referer- http-//tplinkwifi.net to the the request, it will be recognized as passing the authentication.
99
reference:
1010
- https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/WR840N%20v6/ACL%20bypass%20Vulnerability%20in%20TP-Link%20TL-WR840N.md
11+
- https://nvd.nist.gov/vuln/detail/CVE-2024-57050
1112
classification:
1213
cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
1314
cvss-score: 9.8
@@ -34,6 +35,8 @@ http:
3435
part: body
3536
words:
3637
- "$.ret=0;"
38+
- "var "
39+
condition: and
3740

3841
- type: word
3942
part: content_type

0 commit comments

Comments
 (0)