CVE-2020-36178: Command Injection
oaliptaddBridgeIsolationRules on TP-Link TL-WR840N 6EU0.9.14.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oaliptaddBridgeIsolationRules is not the only function that calls utilexecSystem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-36178?
The severity of CVE-2020-36178 is critical.
How does CVE-2020-36178 allow OS command injection?
CVE-2020-36178 allows OS command injection by using a raw string from the web interface for a call to the system library function.
Which devices are affected by CVE-2020-36178?
TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices are affected by CVE-2020-36178.
How can I fix CVE-2020-36178?
To fix CVE-2020-36178, update the firmware of your TP-Link TL-WR840N 6_EU_0.9.1_4.16 device to a non-vulnerable version.
Where can I find more information about CVE-2020-36178?
You can find more information about CVE-2020-36178 at the following references: [link1], [link2], [link3].