Note:
This project will be discontinued after December 13, 2021. [more]
Product:
Tl\-Wdr4300_firmware
(Tp\-Link)Repositories |
Unknown: This might be proprietary software. |
#Vulnerabilities | 5 |
Date | Id | Summary | Products | Score | Patch | Annotated |
---|---|---|---|---|---|---|
2019-11-13 | CVE-2013-4654 | Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND.. | Tl\-1043nd_firmware, Tl\-Wdr4300_firmware | N/A | ||
2019-10-25 | CVE-2013-4848 | TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities. | Tl\-Wdr4300_firmware | N/A | ||
2019-01-18 | CVE-2019-6487 | TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field. | Tl\-Wdr3500_firmware, Tl\-Wdr3600_firmware, Tl\-Wdr4300_firmware, Tl\-Wdr4900_firmware, Tl\-Wdr5620_firmware | 8.8 | ||
2014-09-30 | CVE-2014-4728 | The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request. | Tl\-Wdr4300, Tl\-Wdr4300_firmware | N/A | ||
2014-09-30 | CVE-2014-4727 | Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request. | Tl\-Wdr4300, Tl\-Wdr4300_firmware | N/A |