CVE-2019-12104: Command Injection
Published Aug 14, 2019
·Updated
The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by several post-authentication command injection vulnerabilities.
Affected Software
2 affected components
TP-Link M7350 Firmware<190531
TP-Link M7350=v3
Remediation
Event History
Aug 14, 2019
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
Description
Invalid Date
News Published
Invalid Date
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
1
What is the severity of CVE-2019-12104?
CVE-2019-12104 is categorized with a high severity level due to its potential for command injection post-authentication.
2
How do I fix CVE-2019-12104?
To fix CVE-2019-12104, update the TP-Link M7350 V3 firmware to version 190531 or later.
3
What type of vulnerability is CVE-2019-12104?
CVE-2019-12104 is a command injection vulnerability affecting the web-based configuration interface.
4
Who is affected by CVE-2019-12104?
Users of TP-Link M7350 V3 with firmware versions prior to 190531 are affected by CVE-2019-12104.
5
Can CVE-2019-12104 be exploited remotely?
CVE-2019-12104 requires an authenticated user to exploit the command injection vulnerabilities.