Описание
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Уязвимые конфигурации
Конфигурация 1Версия до 260528 (исключая)
Одновременно
cpe:2.3:o:tp-link:tl-wr940n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr940n:v6:*:*:*:*:*:*:*
EPSS
Процентиль: 85%
0.02787
Низкий
7.2 High
CVSS3
Дефекты
CWE-78
Связанные уязвимости
CVSS3: 7.2
github
около 2 месяцев назад
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
EPSS
Процентиль: 85%
0.02787
Низкий
7.2 High
CVSS3
Дефекты
CWE-78