CVE-2022-25060: OS Command Injection
Published Feb 25, 2022
·Updated
TP-LINK TL-WR840N(ES)V6.20180709 was discovered to contain a command injection vulnerability via the component oalstartPing.
Affected Software
4 affected components
TP-Link Tl-wr840n Firmware=6.20_180709
TP-Link TL-WR840N
All of the following
TP-Link Tl-wr840n Firmware=6.20_180709
TP-Link TL-WR840N
Event History
Feb 25, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-25060?
CVE-2022-25060 is a command injection vulnerability found in TP-LINK TL-WR840N(ES) V6.20_180709 firmware.
2
How severe is CVE-2022-25060?
CVE-2022-25060 has a severity rating of 9.8, which is considered critical.
3
What is the affected software version of CVE-2022-25060?
The affected software version of CVE-2022-25060 is TP-LINK TL-WR840N(ES) V6.20_180709 firmware.
4
How can I fix CVE-2022-25060?
To fix CVE-2022-25060, it is recommended to update to a patched version of TP-LINK TL-WR840N(ES) firmware when available.
5
What is CWE-77 and CWE-78?
CWE-77 and CWE-78 are common weaknesses related to command injection vulnerabilities.