Vulnerability record · CVE-2017-13772 · published 23 October 2017
CVE-2017-13772: TP-Link WR940N router stack buffer overflow via web parameters
Tp Link · Wr940n Firmware
TP-Link WR940N WiFi routers (hardware version 4) contain multiple stack-based buffer overflows in the web management interface. The ping_addr parameter to PingIframeRpm.htm and the dnsserver2 parameter to WanStaticIpV6CfgRpm.htm can be overflowed by a remote authenticated user, leading to arbitrary code execution on the device.
Description
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityRemote authenticated code execution with a high CVSS score and high EPSS probability, though exploitation requires valid credentials and the device is not in KEV.
What it is
TP-Link WR940N WiFi routers (hardware version 4) contain multiple stack-based buffer overflows in the web management interface. The ping_addr parameter to PingIframeRpm.htm and the dnsserver2 parameter to WanStaticIpV6CfgRpm.htm can be overflowed by a remote authenticated user, leading to arbitrary code execution on the device.
Impact
An attacker with valid router credentials gains arbitrary code execution on the device, giving full control of the router's network traffic, configuration and any connected clients.
Attack surface
Reached over the network through the router's HTTP web management interface; the CVSS vector (AV:N/PR:L/UI:N) indicates the attacker must be authenticated but no user interaction is required.
Exploitation
Not listed in CISA KEV, but EPSS is high (0.514, ~98.9th percentile) and public exploit code exists on Exploit-DB (43022) and Packet Storm, so exploitation is feasible and likely.
What to do
- Apply the vendor firmware fix for WR940N hardware version 4; if no fix is available, replace or retire the device.
- Restrict access to the router web management interface to trusted management networks and disable remote/WAN administration.
- Change default and weak administrative credentials and enforce strong unique passwords.
- Segment or isolate the router from sensitive internal networks to limit post-exploitation reach.
Detection
- Monitor router and perimeter logs for requests to PingIframeRpm.htm or WanStaticIpV6CfgRpm.htm with unusually long ping_addr or dnsserver2 parameter values.
- Alert on unexpected outbound connections or configuration changes originating from the router.
- Watch for router reboots, crashes or process restarts that may indicate failed overflow attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/158999/TP-Link-WDR4300-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/43022/ | Third Party AdvisoryVDB Entry |
| https://www.fidusinfosec.com/tp-link-remote-code-execution-cve-2017-13772/ | Third Party Advisory |
| http://packetstormsecurity.com/files/158999/TP-Link-WDR4300-Remote-Code-Execution.html | |
| https://www.exploit-db.com/exploits/43022/ | Third Party AdvisoryVDB Entry |
| https://www.fidusinfosec.com/tp-link-remote-code-execution-cve-2017-13772/ | Third Party Advisory |
Track CVE-2017-13772 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-13772), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.