vendor:
TL-WA850RE Wi-Fi Range Extender
by:
yoresongo - Advisability S.A.S Colombia
8.8
CVSS
HIGH
Command Injection
78
CWE
Product Name: TL-WA850RE Wi-Fi Range Extender
Affected Version From: TL-WA850RE_V5_180228
Affected Version To: TL-WA850RE_V5_180228
Patch Exists: YES
Related CWE: N/A
CPE: h:tp-link:tl-wa850re
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2018
TP-Link Technologies TL-WA850RE Wi-Fi Range Extender – Command Execution
This exploit allows an attacker to execute arbitrary commands on the TP-Link Technologies TL-WA850RE Wi-Fi Range Extender. The exploit is achieved by sending a specially crafted HTTP request to the device, which contains a command injection payload. The payload is then executed by the device.
Mitigation:
The user should ensure that the device is running the latest version of the firmware and that all security patches are applied.