CVE-2019-6487: OS Command Injection
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather getweatherobserve citycode field.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-6487?
CVE-2019-6487 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2019-6487?
To fix CVE-2019-6487, you should update the firmware of affected TP-Link WDR devices to the latest version that addresses this vulnerability.
What devices are affected by CVE-2019-6487?
CVE-2019-6487 affects TP-Link WDR series devices with firmware versions up to and including v3.0.
What type of vulnerability is CVE-2019-6487?
CVE-2019-6487 is a command injection vulnerability that allows attackers to execute arbitrary code on the device.
Can CVE-2019-6487 be exploited remotely?
Yes, CVE-2019-6487 can be exploited remotely after a user logs in to the affected device.