TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
tp-link tl-wdr5620_firmware |
||
tp-link tl-wdr3500_firmware |
||
tp-link tl-wdr3600_firmware |
||
tp-link tl-wdr4300_firmware |
||
tp-link tl-wdr4900_firmware |