CVE-2019-6487
18.01.2019, 10:29
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
Vendor | Product | Version |
---|---|---|
tp-link | tl-wdr5620_firmware | 𝑥 ≤ 3.0 |
tp-link | tl-wdr3500_firmware | 𝑥 ≤ 3.0 |
tp-link | tl-wdr3600_firmware | 𝑥 ≤ 3.0 |
tp-link | tl-wdr4300_firmware | 𝑥 ≤ 3.0 |
tp-link | tl-wdr4900_firmware | 𝑥 ≤ 3.0 |
𝑥
= Vulnerable software versions