CVE-2018-11481
30.05.2018, 21:29
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.Enginsight
Vendor | Product | Version |
---|---|---|
tp-link | ipc_tl-ipc223\(p\)-6_firmware | 𝑥 < 1.0.21 |
tp-link | tl-ipc323k-d_firmware | 𝑥 < 1.0.21 |
tp-link | tl-ipc325\(kp\)_firmware | 𝑥 < 1.0.21 |
tp-link | tl-ipc40a-4_firmware | 𝑥 < 1.0.21 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration