Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ppr5-j2r8-wqw5

Опубликовано: 12 мар. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 8.8

Описание

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

EPSS

Процентиль: 76%
0.01774
Низкий

8.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78

Связанные уязвимости

CVSS3: 8.8
nvd
5 месяцев назад

A command injection vulnerability has been identified in the Telnet command-line interface (CLI) of TP-Link TL-MR6400 v5.3. This issue is caused by insufficient sanitization of data processed during specific CLI operations. An authenticated attacker with elevated privileges may be able to execute arbitrary system commands. Successful exploitation may lead to full device compromise, including potential loss of confidentiality, integrity, and availability.

CVSS3: 7.2
fstec
5 месяцев назад

Уязвимость интерфейса командной строки (CLI) Telnet микропрограммного обеспечения маршрутизаторов TP-Link TL-MR6400 v5.3, позволяющая нарушителю выполнять произвольные системные команды

EPSS

Процентиль: 76%
0.01774
Низкий

8.5 High

CVSS4

8.8 High

CVSS3

Дефекты

CWE-78