Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.
CVSS Vector
AV:N/AC:M/Au:N/C:N/I:P/A:NTp Link Tl Wdr4300
HWTp-Linkall versionsTp Link Tl Wdr4300 Firmware
OSTp-Link≤ 130617
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
XSS
CWE
References
Related vulnerabilities
CVE-2013-4654CRITICAL9.8PL ✓same product
Symlink Traversal w firmware routerów TP-LINK TL-WDR4300 i TL-1043ND
CVE-2015-3035HIGH7.5⚠ KEVsame product
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmwa...
CVE-2013-4848HIGH8.8same product
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
CVE-2019-6487HIGH8.8same product
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (af...
CVE-2023-50224MEDIUM6.5⚠ KEVsame product
TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability...