CVE-2020-9374

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
24/02/2020
Last modified:
01/01/2022

Description

On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tl-wr849n_firmware:0.9.1_4.16:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr849n:-:*:*:*:*:*:*:*