CVE-2019-13649: Command Injection
Published Oct 24, 2019
·Updated
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).
Affected Software
2 affected components
TP-Link M7350 Firmware<=1.0.16
TP-Link M7350
Event History
Oct 24, 2019
CVE Published
via MITRE·02:54 PM
Data Sourced
via MITRE·02:54 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13649?
CVE-2019-13649 has a medium severity rating due to its potential for OS command injection on TP-Link M7350 devices.
2
How do I fix CVE-2019-13649?
To fix CVE-2019-13649, upgrade the TP-Link M7350 firmware to a version later than 1.0.16.
3
What devices are affected by CVE-2019-13649?
CVE-2019-13649 affects TP-Link M7350 devices running firmware version 1.0.16 or earlier.
4
What kind of attack can CVE-2019-13649 enable?
CVE-2019-13649 can enable attackers to perform OS command injection, potentially leading to device compromise.
5
Is CVE-2019-13649 exploitable remotely?
Yes, CVE-2019-13649 is exploitable by external attackers due to inadequate input validation.