CVE-2019-15060: OS Command Injection
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this TP-Link router vulnerability?
The vulnerability ID for this TP-Link TL-WR840N v4 router vulnerability is CVE-2019-15060.
What is the severity rating of CVE-2019-15060?
The severity rating of CVE-2019-15060 is 8.8 (High).
How does the vulnerability in the TP-Link TL-WR840N v4 router with firmware 0.9.1 3.16 occur?
The vulnerability in the TP-Link TL-WR840N v4 router occurs due to a remote code execution vulnerability in the traceroute function, which can be exploited via a crafted payload in an IP address input field.
What is the affected software version for this TP-Link vulnerability?
The affected software version for this TP-Link vulnerability is TL-WR840N firmware up to and including version 0.9.1 3.16.
How can I fix the CVE-2019-15060 vulnerability in my TP-Link TL-WR840N v4 router?
To fix the CVE-2019-15060 vulnerability in your TP-Link TL-WR840N v4 router, update the firmware to a version that addresses the vulnerability.