CVE-2018-12577: OS Command Injection
Published Jul 2, 2018
·Updated
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
Affected Software
2 affected components
TP-Link TL-WR841N firmware=0.9.1_4.16
TP-Link TL-WR841N=13.0
Event History
Jul 2, 2018
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is CVE-2018-12577?
CVE-2018-12577 is a vulnerability that allows authenticated blind Command Injection on TP-Link TL-WR841N v13 routers.
2
What is the severity of CVE-2018-12577?
The severity of CVE-2018-12577 is high, with a CVSS base score of 8.8.
3
How can I check if my TP-Link TL-WR841N v13 router is affected?
You can check if your TP-Link TL-WR841N v13 router is affected by CVE-2018-12577 by verifying the firmware version matches '0.9.1_4.16'.
4
How do I fix CVE-2018-12577?
To fix CVE-2018-12577, TP-Link TL-WR841N v13 router users should update to firmware version 0.9.1_4.16 or newer.
5
Where can I find more information about CVE-2018-12577?
You can find more information about CVE-2018-12577 at the following URL: https://software-talk.org/blog/2018/06/tplink-wr841n-code-exec-cve-2018-12577/