The default configuration of the TP-Link 8840T router enables web-based administration on the WAN interface, which allows remote attackers to establish an HTTP connection and possibly have unspecified other impact via unknown vectors.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | 8840t | - |
Directory traversal vulnerability in the web-based management feature on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to the help/ URI.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | * |
| tp-link | tl-wr841n | - |
Directory traversal vulnerability in the web-based management interface on the TP-LINK TL-WR841N router with firmware 3.13.9 build 120201 Rel.54965n and earlier allows remote attackers to read arbitrary files via the URL parameter.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n | - |
| tp-link | tl-wr841n_firmware | 3.13.9 |
Multiple cross-site scripting (XSS) vulnerabilities in the TP-LINK TL-WR841N router with firmware 3.13.9 Build 120201 Rel.54965n and earlier allow remote administrators to inject arbitrary web script or HTML via the (1) username or (2) pwd parameter to userRpm/NoipDdnsRpm.htm.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | * |
| tp-link | tl-wr841n | - |
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitrary commands via shell metacharacters in (1) the ServerName parameter and (2) other unspecified parameters.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sc3171g | - |
| tp-link | lm_firmware | * |
| tp-link | tl-sc3130g | - |
| tp-link | tl-sc3171 | - |
| tp-link | tl-sc3130 | - |
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a TELNET session.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-255,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sc3171g | - |
| tp-link | lm_firmware | * |
| tp-link | tl-sc3130g | - |
| tp-link | tl-sc3171 | - |
| tp-link | tl-sc3130 | - |
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, allows remote attackers to upload arbitrary files, then accessing it via a direct request to the file in the mnt/mtd directory.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-Other,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sc3171g | - |
| tp-link | lm_firmware | * |
| tp-link | tl-sc3130g | - |
| tp-link | tl-sc3171 | - |
| tp-link | tl-sc3130 | - |
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the firmware revision via a "preset" action.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sc3171g | - |
| tp-link | lm_firmware | * |
| tp-link | tl-sc3130g | - |
| tp-link | tl-sc3171 | - |
| tp-link | tl-sc3130 | - |
Multiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote attackers to hijack the authentication of administrators for requests that (1) enable FTP access (aka "FTP directory traversal") to /tmp via the shareEntire parameter to userRpm/NasFtpCfgRpm.htm, (2) change the FTP administrative password via the nas_admin_pwd parameter to userRpm/NasUserAdvRpm.htm, (3) enable FTP on the WAN interface via the internetA parameter to userRpm/NasFtpCfgRpm.htm, (4) launch the FTP service via the startFtp parameter to userRpm/NasFtpCfgRpm.htm, or (5) enable or disable bandwidth limits via the QoSCtrl parameter to userRpm/QoSCfgRpm.htm.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | firmware | tl-wr1043nd_v1_120405 |
The TP-Link IP Cameras TL-SC3171, TL-SC3130, TL-SC3130G, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, does not properly restrict access to certain administrative functions, which allows remote attackers to (1) cause a denial of service (device reboot) via a request to cgi-bin/reboot or (2) cause a denial of service (reboot and reset to factory defaults) via a request to cgi-bin/hardfactorydefault.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-264,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sc3171g | - |
| tp-link | lm_firmware | * |
| tp-link | tl-sc3130g | - |
| tp-link | tl-sc3171 | - |
| tp-link | tl-sc3130 | - |
Cross-site scripting (XSS) vulnerability in Allegro RomPager before 4.51, as used on the ZyXEL P660HW-D1, Huawei MT882, Sitecom WL-174, TP-LINK TD-8816, and D-Link DSL-2640R and DSL-2641R, when the "forbidden author header" protection mechanism is bypassed, allows remote attackers to inject arbitrary web script or HTML by requesting a nonexistent URI in conjunction with a crafted HTTP Referer header that is not properly handled in a 404 page. NOTE: there is no CVE for a "URL redirection" issue that some sources list separately.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | td-8816 | - |
| zyxel | p-660hw_d1 | - |
| sitecom | wl-174 | - |
| dlink | dsl-2640r | - |
| dlink | dsl-2641r | - |
| allegrosoft | rompager | * |
| huawei | mt882 | - |
Cross-site scripting (XSS) vulnerability in the DHCP clients page in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to inject arbitrary web script or HTML via the hostname in a DHCP request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wdr4300_firmware | * |
| tp-link | tl-wdr4300 | - |
The web server in the TP-LINK N750 Wireless Dual Band Gigabit Router (TL-WDR4300) with firmware before 140916 allows remote attackers to cause a denial of service (crash) via a long header in a GET request.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-399,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wdr4300_firmware | * |
| tp-link | tl-wdr4300 | - |
TP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of service (httpd crash) via vectors involving a "new" value in the isNew parameter to PingIframeRpm.htm.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-19,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr740n_firmware | 3.17.0 |
| tp-link | tl-wr740n | 4 |
| tp-link | tl-wr740n_firmware | 3.16.6 |
| tp-link | tl-wr740n_firmware | 3.16.4 |
Cross-site request forgery (CSRF) vulnerability in the administration console in TP-Link TL-WR840N (V1) router with firmware before 3.13.27 build 141120 allows remote attackers to hijack the authentication of administrators for requests that change router settings via a configuration file import.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr840n_firmware | 3.13.27 |
Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmware before 150304, and C8 (1.0) with firmware before 150316, Archer C9 (1.0), TL-WDR3500 (1.0), TL-WDR3600 (1.0), and TL-WDR4300 (1.0) with firmware before 150302, TL-WR740N (5.0) and TL-WR741ND (5.0) with firmware before 150312, and TL-WR841N (9.0), TL-WR841N (10.0), TL-WR841ND (9.0), and TL-WR841ND (10.0) with firmware before 150310 allows remote attackers to read arbitrary files via a .. (dot dot) in the PATH_INFO to login/.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| 134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
| nvd@nist.gov | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 3.9 | 3.6 |
CVSS 2.0
Severity: HIGH
Problem Type: CWE-22,CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | * |
| tp-link | tl-wdr3500_firmware | * |
| tp-link | tl-wdr4300_firmware | * |
| tp-link | tl-wr741nd_firmware | * |
| tp-link | tl-wr740n_firmware | * |
| tp-link | archer_c7_firmware | * |
| tp-link | archer_c5_firmware | * |
| tp-link | tl-wr841nd_firmware | * |
| tp-link | archer_c9_firmware | * |
| tp-link | archer_c8_firmware | * |
| tp-link | tl-wdr3600_firmware | * |
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-254,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tp-link | - |
On TP-Link NC250 devices with firmware through 1.2.1 build 170515, anyone can view video and audio without authentication via an rtsp://admin@yourip:554/h264_hd.sdp URL.
CVSS 3.x
| Source | Score | Severity | Vector | Exploitability | Impact |
|---|---|---|---|---|---|
| nvd@nist.gov | 6.5 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | 2.8 | 3.6 |
CVSS 2.0
Severity: LOW
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | nc250_firmware | * |
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-335,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | archer_c9_(2.0)_firmware | 160517 |
Multiple stack-based buffer overflows in TP-Link WR940N WiFi routers with hardware version 4 allow remote authenticated users to execute arbitrary code via the (1) ping_addr parameter to PingIframeRpm.htm or (2) dnsserver2 parameter to WanStaticIpV6CfgRpm.htm.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wr940n_firmware | - |
Cross-site scripting (XSS) vulnerability in the Wireless MAC Filtering page in TP-LINK TL-MR3220 wireless routers allows remote attackers to inject arbitrary web script or HTML via the Description field.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-mr3220_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the cmxddns.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-outif variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-zone variable in the ipmac_import.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the olmode variable in the interface_wan.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-authtype variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-olmode variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-bindif variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-pns variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-tunnelname variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-remotesubnet variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | war2600l_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | r4149g_firmware | - |
| tp-link | er5510g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | war458l_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | wvr458l_firmware | - |
| tp-link | r478_firmware | - |
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file.
CVSS 2.0
Severity: HIGH
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wvr4300l_firmware | - |
| tp-link | r4299g_firmware | - |
| tp-link | r478g+_firmware | - |
| tp-link | r488_firmware | - |
| tp-link | er5110g_firmware | - |
| tp-link | wvr1300l_firmware | - |
| tp-link | war1750l_firmware | - |
| tp-link | r4239g_firmware | - |
| tp-link | war1300l_firmware | - |
| tp-link | r483_firmware | - |
| tp-link | wvr2600l_firmware | - |
| tp-link | wvr1750l_firmware | - |
| tp-link | r483g_firmware | - |
| tp-link | r473p-ac_firmware | - |
| tp-link | wvr450_firmware | - |
| tp-link | wvr302_firmware | - |
| tp-link | war2600l_firmware | - |
| tp-link | wvr900g_firmware | 3.0_170306 |
| tp-link | er5510g_firmware | - |
| tp-link | r4149g_firmware | - |
| tp-link | war900l_firmware | - |
| tp-link | war450_firmware | - |
| tp-link | r478+_firmware | - |
| tp-link | r473_firmware | - |
| tp-link | wvr900l_firmware | - |
| tp-link | r473g_firmware | - |
| tp-link | wvr300_firmware | - |
| tp-link | war302_firmware | - |
| tp-link | er5520g_firmware | - |
| tp-link | er5120g_firmware | - |
| tp-link | wvr1300g_firmware | - |
| tp-link | wvr450l_firmware | 1.0161125 |
| tp-link | war458l_firmware | - |
| tp-link | r473gp-ac_firmware | - |
| tp-link | war458_firmware | - |
| tp-link | war450l_firmware | - |
| tp-link | r478_firmware | - |
| tp-link | wvr458l_firmware | - |
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /usr/lib/lua/luci/controller/admin/diagnostic.lua in uhttpd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-er6110g_firmware | - |
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-war302_firmware | - |
| tp-link | tl-r473_firmware | - |
| tp-link | tl-er5110g_firmware | - |
| tp-link | tl-war458_firmware | - |
| tp-link | tl-er5510g_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-r479gpe-ac_firmware | - |
| tp-link | tl-r4299g_firmware | - |
| tp-link | tl-wvr900g_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-wvr458p_firmware | - |
| tp-link | tl-wvr458_firmware | - |
| tp-link | tl-er6120g_firmware | - |
| tp-link | tl-r479p-ac_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-er5520g_firmware | - |
| tp-link | tl-r478+_firmware | - |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-r473p-ac_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-er5120g_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
| tp-link | tl-wvr1300g_firmware | - |
| tp-link | tl-r4149g_firmware | - |
| tp-link | tl-er6520g_firmware | - |
| tp-link | tl-r478g_firmware | - |
| tp-link | tl-r478g+_firmware | - |
| tp-link | tl-r473g_firmware | - |
| tp-link | tl-er3210g_firmware | - |
| tp-link | tl-wvr300_firmware | - |
| tp-link | tl-er6510g_firmware | - |
| tp-link | tl-wvr450_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-wvr450g_firmware | - |
| tp-link | tl-r479gp-ac_firmware | - |
| tp-link | tl-r483_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-wvr302_firmware | - |
| tp-link | tl-er7520g_firmware | - |
| tp-link | tl-r488_firmware | - |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-r478_firmware | - |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-er6220g_firmware | - |
| tp-link | tl-war450_firmware | - |
| tp-link | tl-r4239g_firmware | - |
| tp-link | tl-er3220g_firmware | - |
| tp-link | tl-r483g_firmware | - |
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/bridge.lua in uhttpd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-er6110g_firmware | - |
| tp-link | tl-war302_firmware | - |
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-r473_firmware | - |
| tp-link | tl-er5110g_firmware | - |
| tp-link | tl-war458_firmware | - |
| tp-link | tl-er5510g_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-r479gpe-ac_firmware | - |
| tp-link | tl-wvr900g_firmware | - |
| tp-link | tl-r4299g_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-wvr458p_firmware | - |
| tp-link | tl-wvr458_firmware | - |
| tp-link | tl-er6120g_firmware | - |
| tp-link | tl-r479p-ac_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-r478+_firmware | - |
| tp-link | tl-er5520g_firmware | - |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-r473p-ac_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-er5120g_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
| tp-link | tl-wvr1300g_firmware | - |
| tp-link | tl-r4149g_firmware | - |
| tp-link | tl-er6520g_firmware | - |
| tp-link | tl-r478g_firmware | - |
| tp-link | tl-r473g_firmware | - |
| tp-link | tl-r478g+_firmware | - |
| tp-link | tl-er3210g_firmware | - |
| tp-link | tl-er6510g_firmware | - |
| tp-link | tl-wvr300_firmware | - |
| tp-link | tl-wvr450_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-wvr450g_firmware | - |
| tp-link | tl-r483_firmware | - |
| tp-link | tl-r479gp-ac_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-wvr302_firmware | - |
| tp-link | tl-er7520g_firmware | - |
| tp-link | tl-r488_firmware | - |
| tp-link | tl-r478_firmware | - |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-er6220g_firmware | - |
| tp-link | tl-war450_firmware | - |
| tp-link | tl-r4239g_firmware | - |
| tp-link | tl-r483g_firmware | - |
| tp-link | tl-er3220g_firmware | - |
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted Accept-Language HTTP header, related to the set_sysinfo and get_sysinfo functions in /usr/lib/lua/luci/controller/locale.lua in uhttpd.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-22,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-er6110g_firmware | - |
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-war302_firmware | - |
| tp-link | tl-r473_firmware | - |
| tp-link | tl-er5110g_firmware | - |
| tp-link | tl-war458_firmware | - |
| tp-link | tl-er5510g_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-r479gpe-ac_firmware | - |
| tp-link | tl-wvr900g_firmware | - |
| tp-link | tl-r4299g_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-wvr458p_firmware | - |
| tp-link | tl-wvr458_firmware | - |
| tp-link | tl-r479p-ac_firmware | - |
| tp-link | tl-er6120g_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-r478+_firmware | - |
| tp-link | tl-er5520g_firmware | - |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-er5120g_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-r473p-ac_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
| tp-link | tl-wvr1300g_firmware | - |
| tp-link | tl-r4149g_firmware | - |
| tp-link | tl-er6520g_firmware | - |
| tp-link | tl-r478g_firmware | - |
| tp-link | tl-r473g_firmware | - |
| tp-link | tl-r478g+_firmware | - |
| tp-link | tl-er3210g_firmware | - |
| tp-link | tl-wvr300_firmware | - |
| tp-link | tl-er6510g_firmware | - |
| tp-link | tl-wvr450_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-wvr450g_firmware | - |
| tp-link | tl-r483_firmware | - |
| tp-link | tl-r479gp-ac_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-wvr302_firmware | - |
| tp-link | tl-er7520g_firmware | - |
| tp-link | tl-r488_firmware | - |
| tp-link | tl-r478_firmware | - |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-er6220g_firmware | - |
| tp-link | tl-war450_firmware | - |
| tp-link | tl-r4239g_firmware | - |
| tp-link | tl-r483g_firmware | - |
| tp-link | tl-er3220g_firmware | - |
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/interface.lua in uhttpd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-er5510g | v3 |
| tp-link | tl-er6110g_firmware | - |
| tp-link | tl-er6520g | v3 |
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-war302_firmware | - |
| tp-link | tl-r483 | v5 |
| tp-link | tl-er5110g_firmware | - |
| tp-link | tl-war458_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-wvr300 | v4 |
| tp-link | tl-r479gpe-ac_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-er5510g | v2 |
| tp-link | tl-r478 | v6 |
| tp-link | tl-wvr450g | v5 |
| tp-link | tl-wvr458p_firmware | - |
| tp-link | tl-r4239g | v2 |
| tp-link | tl-wvr458_firmware | - |
| tp-link | tl-r479p-ac_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-r473gp-ac_firmware | - |
| tp-link | tl-wvr302 | v2 |
| tp-link | tl-er5520g | v2 |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-er3220g_firmware | * |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-r473p-ac_firmware | - |
| tp-link | tl-er5120g_firmware | - |
| tp-link | tl-wvr1300g_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
| tp-link | tl-r4149g_firmware | - |
| tp-link | tl-er6120g | v2 |
| tp-link | tl-r473g_firmware | - |
| tp-link | tl-r478g_firmware | - |
| tp-link | tl-er3210g_firmware | - |
| tp-link | tl-er6510g_firmware | - |
| tp-link | tl-er5520g | v3 |
| tp-link | tl-r483g | v2 |
| tp-link | tl-wvr450_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-r478+ | v7 |
| tp-link | tl-r479gp-ac_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-er7520g_firmware | - |
| tp-link | tl-r4299g | v2 |
| tp-link | tl-wvr900g | v3 |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-r488 | v5 |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-r473 | v5 |
| tp-link | tl-r478g+ | v3 |
| tp-link | tl-wvr2600l_firmware | - |
| tp-link | tl-er6220g_firmware | - |
| tp-link | tl-war450_firmware | - |
| tp-link | tl-er6520g | v2 |
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.0.0 |
Weak access control methods on the TP-Link TL-SG108E 1.0.0 allow any user on a NAT network with an authenticated administrator to access the device without entering user credentials. The authentication record is stored on the device; thus if an administrator authenticates from a NAT network, the authentication applies to the IP address of the NAT gateway, and any user behind that NAT gateway is also treated as authenticated.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.0.0 |
Weak access controls in the Device Logout functionality on the TP-Link TL-SG108E v1.0.0 allow remote attackers to call the logout functionality, triggering a denial of service condition.
CVSS 2.0
Severity: LOW
Problem Type: CWE-306,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.0.0 |
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/wportal command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/lua/luci/controller/admin/wportal.lua in uhttpd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-wvr2600l_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
TP-Link TL-WVR and TL-WAR devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the interface field of an admin/dhcps command to cgi-bin/luci, related to the zone_get_iface_bydev function in /usr/lib/lua/luci/controller/admin/dhcps.lua in uhttpd.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wvr900l_firmware | - |
| tp-link | tl-war900l_firmware | - |
| tp-link | tl-war450l_firmware | - |
| tp-link | tl-war458l_firmware | - |
| tp-link | tl-wvr4300l_firmware | - |
| tp-link | tl-wvr1750l_firmware | - |
| tp-link | tl-wvr1300l_firmware | - |
| tp-link | tl-wvr2600l_firmware | - |
| tp-link | tl-war2600l_firmware | - |
| tp-link | tl-wvr458l_firmware | - |
| tp-link | tl-war1750l_firmware | - |
| tp-link | tl-war1200l_firmware | - |
| tp-link | tl-wvr1200l_firmware | - |
| tp-link | tl-war1300l_firmware | - |
| tp-link | tl-wvr450l_firmware | - |
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "SEND data" log lines where passwords are encoded in hexadecimal. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.1.2 |
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-532,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.1.2 |
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-326,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.1.2 |
On the TP-Link TL-SG108E 1.0, there is a hard-coded ciphering key (a long string beginning with Ei2HNryt). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.1.2 |
On the TP-Link TL-SG108E 1.0, the upgrade process can be requested remotely without authentication (httpupg.cgi with a parameter called cmd). This affects the 1.1.2 Build 20141017 Rel.50749 firmware.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-sg108e_firmware | 1.1.2 |
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-862,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | c2_firmware | * |
| tp-link | c20i_firmware | * |
vsftpd on TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n has a backdoor admin account with the 1234 password, a backdoor guest account with the guest password, and a backdoor test account with the test password.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-1188,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | c2_firmware | * |
| tp-link | c20i_firmware | * |
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | c2_firmware | * |
| tp-link | c20i_firmware | * |
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow remote code execution with a single HTTP request by placing shell commands in a "host=" line within HTTP POST data.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | c2_firmware | * |
| tp-link | c20i_firmware | * |
The executable httpd on the TP-Link WR841N V8 router before TL-WR841N(UN)_V8_170210 contained a design flaw in the use of DES for block encryption. This resulted in incorrect access control, which allowed attackers to gain read-write access to system settings through the protected router configuration service tddp via the LAN and Ath0 (Wi-Fi) interfaces.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-327,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wr841n_v8_firmware | * |
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. This is fixed in version 2.6.1_Windows.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | eap_controller | 2.6.0 |
| tp-link | eap_controller | 2.5.4 |
Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. This is fixed in version 2.6.1_Windows.
CVSS 2.0
Severity: LOW
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | eap_controller | 2.6.0 |
| tp-link | eap_controller | 2.5.4 |
The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. This would allow an attacker to submit authenticated requests when an authenticated user browses an attack-controlled domain. This is fixed in version 2.6.1_Windows.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | eap_controller | 2.6.0 |
| tp-link | eap_controller | 2.5.4 |
The web application backup file in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows is encrypted with a hard-coded cryptographic key, so anyone who knows that key and the algorithm can decrypt it. A low-privilege user could decrypt and modify the backup file in order to elevate their privileges. This is fixed in version 2.6.1_Windows.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | eap_controller | 2.6.0 |
| tp-link | eap_controller | 2.5.4 |
TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows do not control privileges for usage of the Web API, allowing a low-privilege user to make any request as an Administrator. This is fixed in version 2.6.1_Windows.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-269,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | eap_controller | 2.6.0 |
| tp-link | eap_controller | 2.5.4 |
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | ipc_tl-ipc223(p)-6_firmware | * |
| tp-link | tl-ipc40a-4_firmware | * |
| tp-link | tl-ipc323k-d_firmware | * |
| tp-link | tl-ipc325(kp)_firmware | * |
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-798,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | ipc_tl-ipc223(p)-6_firmware | * |
| tp-link | tl-ipc40a-4_firmware | * |
| tp-link | tl-ipc323k-d_firmware | * |
| tp-link | tl-ipc325(kp)_firmware | * |
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker sends a header of "Referer: http://192.168.0.1/mainFrame.htm" then no authentication is required for any action.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-384,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | 0.9.1_4.16 |
| tp-link | tl-wr840n_firmware | 0.9.1_3.16 |
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-352,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | 0.9.1_4.16 |
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-287,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | 0.9.1_4.16 |
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-1021,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | 0.9.1_4.16 |
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr841n_firmware | 0.9.1_4.16 |
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-78,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wa850re_firmware | - |
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /data/syslog.filter.json.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-787,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wa850re_firmware | - |
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.
CVSS 2.0
Severity: HIGH
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wa850re_firmware | - |
TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-79,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | archer_c1200_firmware | 1.13 |
TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-20,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | wr840n | - |
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
CVSS 2.0
Severity: MEDIUM
Problem Type: CWE-119,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr840n_firmware | 0.9.1 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wlan_access name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for firewall dmz enable.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for firewall lan_manage mac2.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_wds_2g ssid.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g power.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g isolate.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for wireless wlan_host_2g bandwidth.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for hosts_info para sun.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for hosts_info set_block_flag up_limit.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for protocol wan wan_rate.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for ip_mac_bind name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for ddns phddns username.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for reboot_timer name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for dhcpd udhcpd enable.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |
An issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services (e.g., inetd, HTTP, DNS, and UPnP) via long JSON data for time_switch name.
CVSS 2.0
Severity: MEDIUM
Problem Type: NVD-CWE-noinfo,
Products Affected
| Vendor | Product | Version |
|---|---|---|
| tp-link | tl-wr886n_firmware | 6.0_2.3.4 |
| tp-link | tl-wr886n_firmware | 7.0_1.1.0 |