CVE-2022-25064: OS Command Injection
Published Feb 25, 2022
·Updated
TP-LINK TL-WR840N(ES)V6.20180709 was discovered to contain a remote code execution (RCE) vulnerability via the function oalwan6setIpAddr.
Affected Software
4 affected components
TP-Link Tl-wr840n Firmware=6.20_180709
TP-Link TL-WR840N
All of the following
TP-Link Tl-wr840n Firmware=6.20_180709
TP-Link TL-WR840N
Event History
Feb 25, 2022
CVE Published
via MITRE·07:38 PM
Data Sourced
via MITRE·07:38 PM
Description
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is CVE-2022-25064?
CVE-2022-25064 is a remote code execution (RCE) vulnerability discovered in TP-LINK TL-WR840N(ES)_V6.20_180709 firmware.
2
How severe is CVE-2022-25064?
CVE-2022-25064 has a severity rating of 9.8, which is considered critical.
3
What is the affected software of CVE-2022-25064?
The affected software of CVE-2022-25064 is TP-LINK TL-WR840N(ES)_V6.20_180709 firmware.
4
What is the CWE for CVE-2022-25064?
The CWE (Common Weakness Enumeration) for CVE-2022-25064 is CWE-78, which refers to Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
5
Is TP-LINK TL-WR840N vulnerable to CVE-2022-25064?
Yes, TP-LINK TL-WR840N is vulnerable to CVE-2022-25064.