vendor:
TL-WR841N
by:
Koh You Liang
8,8
CVSS
HIGH
Command Injection
78
CWE
Product Name: TL-WR841N
Affected Version From: TL-WR841N 0.9.1 4.0
Affected Version To: TL-WR841N 0.9.1 4.0
Patch Exists: YES
Related CWE: CVE-2020-35576
CPE: h:tp-link:tl-wr841n
Metasploit:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 10
2020
TP-Link TL-WR841N – Command Injection
A command injection vulnerability exists in TP-Link TL-WR841N 0.9.1 4.0. An attacker can send a malicious payload to the router via a POST request to the /cgi?2 endpoint, which will be executed on the router. This can be exploited to execute arbitrary commands on the router.
Mitigation:
Users should update their router to the latest version to patch this vulnerability.