CVE-2020-28347: OS Command Injection
Published Nov 8, 2020
·Updated
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slavemac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
Affected Software
2 affected components
TP-Link Ac1750 Firmware<201029
TP-Link AC1750=a7
Remediation
Patch Available
Event History
Nov 8, 2020
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-28347.
2
What is the severity of CVE-2020-28347?
The severity of CVE-2020-28347 is critical with a CVSS score of 9.8.
3
Which devices are affected by CVE-2020-28347?
TP-Link Archer A7 AC1750 devices before version 201029 are affected by CVE-2020-28347.
4
How can remote attackers exploit CVE-2020-28347?
Remote attackers can exploit CVE-2020-28347 by executing arbitrary code via the slave_mac parameter.
5
Is there a fix available for CVE-2020-28347?
Yes, upgrading to a version after 201029 will fix CVE-2020-28347.