Post #2344180
2026-04-29 23:53 UTC
TP-Link fireware is a gift that keeps on giving.
https://mrbruh.com/tplink/
TL;DR an undocumented command in the CLI calls out to a TFTP server and trusts whatever is provided because really, why wouldn't you?
Now, of course you need to be authenticated in order to get to the CLI like this; but you gain more control over the machine by exploiting it.
Replies (1)
-
@kusuriya@masto.hackers.town 2026-04-30 00:30
@yojimbo@masto.hackers.town @dch@bsd.network that tftp server is totally trustworthy not shady at all!