Vulnerabilities
Vulnerable Software
Tp-Link:  Security Vulnerabilities
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the tdpServer service, which listens on UDP port 20002 by default. When parsing the slave_mac parameter, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-9650.
CVSS Score
8.8
EPSS Score
0.447
Published
2020-03-25
TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.
CVSS Score
7.5
EPSS Score
0.282
Published
2020-03-25
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.
CVSS Score
9.8
EPSS Score
0.42
Published
2020-02-24
The Web Management of TP-Link TP-SG105E V4 1.0.0 Build 20181120 devices allows an unauthenticated attacker to reboot the device via a reboot.cgi request.
CVSS Score
7.5
EPSS Score
0.378
Published
2020-02-03
TP-LINK TL-WR1043ND V1_120405 devices contain an unspecified denial of service vulnerability.
CVSS Score
7.5
EPSS Score
0.013
Published
2020-02-03
A Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default hard-coded credentials for the administrative Web interface, which could let a malicious user obtain unauthorized access to CGI files.
CVSS Score
7.5
EPSS Score
0.164
Published
2020-01-29
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.
CVSS Score
9.8
EPSS Score
0.422
Published
2020-01-29
TP-LINK TL-WR849N 0.9.1 4.16 devices do not require authentication to replace the firmware via a POST request to the cgi/softup URI.
CVSS Score
6.1
EPSS Score
0.038
Published
2020-01-27
This vulnerability allows remote attackers to execute arbitrary code on affected installations of TP-LINK TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web service, which listens on TCP port 80 by default. When parsing the Host request header, the process does not properly validate the length of user-supplied data prior to copying it to a fixed-length static buffer. An attacker can leverage this vulnerability to execute code in the context of the admin user. Was ZDI-CAN-8457.
CVSS Score
8.8
EPSS Score
0.137
Published
2020-01-07
Symlink Traversal vulnerability in TP-LINK TL-WDR4300 and TL-1043ND..
CVSS Score
9.8
EPSS Score
0.027
Published
2019-11-13


Contact Us

Shodan ® - All rights reserved