First published: Fri Jan 18 2019(Updated: )
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tp-link Tl-wdr5620 Firmware | <=3.0 | |
TP-LINK TL-WDR5620 | ||
Tp-link Tl-wdr3500 Firmware | <=3.0 | |
Tp-link Tl-wdr3500 | ||
Tp-link Tl-wdr3600 Firmware | <=3.0 | |
Tp-link Tl-wdr3600 | ||
Tp-link Tl-wdr4300 Firmware | <=3.0 | |
TP-LINK TL-WDR4300 | ||
Tp-link Tl-wdr4900 Firmware | <=3.0 | |
Tp-link Tl-wdr4900 | ||
All of | ||
Tp-link Tl-wdr5620 Firmware | <=3.0 | |
TP-LINK TL-WDR5620 | ||
All of | ||
Tp-link Tl-wdr3500 Firmware | <=3.0 | |
Tp-link Tl-wdr3500 | ||
All of | ||
Tp-link Tl-wdr3600 Firmware | <=3.0 | |
Tp-link Tl-wdr3600 | ||
All of | ||
Tp-link Tl-wdr4300 Firmware | <=3.0 | |
TP-LINK TL-WDR4300 | ||
All of | ||
Tp-link Tl-wdr4900 Firmware | <=3.0 | |
Tp-link Tl-wdr4900 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-6487 has a critical severity level due to its potential for remote code execution.
To fix CVE-2019-6487, you should update the firmware of affected TP-Link WDR devices to the latest version that addresses this vulnerability.
CVE-2019-6487 affects TP-Link WDR series devices with firmware versions up to and including v3.0.
CVE-2019-6487 is a command injection vulnerability that allows attackers to execute arbitrary code on the device.
Yes, CVE-2019-6487 can be exploited remotely after a user logs in to the affected device.