CVE-2020-35576: OS Command Injection
A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-35576?
CVE-2020-35576 is a Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 that allows authenticated users to execute arbitrary code as root via shell metacharacters.
What is the severity of CVE-2020-35576?
CVE-2020-35576 has a severity rating of 8.8 (Critical).
How does CVE-2020-35576 affect TP-Link TL-WR841N V13 (JP)?
CVE-2020-35576 affects TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216.
How can an authenticated user exploit CVE-2020-35576?
An authenticated user can exploit CVE-2020-35576 by using shell metacharacters in the traceroute feature to execute arbitrary code as root.
Where can I find more information about CVE-2020-35576?
More information about CVE-2020-35576 can be found at the following references: [1] [2] [3].