Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-19537

Опубликовано: 26 нояб. 2018
Источник: nvd
CVSS3: 7.2
CVSS2: 9
EPSS Средний

Описание

TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tp-link:archer_c5_firmware:*:*:*:*:*:*:*:*
Версия до 2_160201_us (включая)
cpe:2.3:h:tp-link:archer_c5:-:*:*:*:*:*:*:*

EPSS

Процентиль: 95%
0.19618
Средний

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434

Связанные уязвимости

CVSS3: 7.2
github
больше 3 лет назад

TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.

EPSS

Процентиль: 95%
0.19618
Средний

7.2 High

CVSS3

9 Critical

CVSS2

Дефекты

CWE-434