First published: Fri Jan 18 2019(Updated: )
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tp-link Tl-wdr5620 Firmware | <=3.0 | |
Tp-link Tl-wdr5620 | ||
Tp-link Tl-wdr3500 Firmware | <=3.0 | |
Tp-link Tl-wdr3500 | ||
Tp-link Tl-wdr3600 Firmware | <=3.0 | |
Tp-link Tl-wdr3600 | ||
Tp-link Tl-wdr4300 Firmware | <=3.0 | |
TP-LINK TL-WDR4300 | ||
Tp-link Tl-wdr4900 Firmware | <=3.0 | |
Tp-link Tl-wdr4900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.