CVE-2020-35576

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
26/01/2021
Last modified:
02/02/2023

Description

A Command Injection issue in the traceroute feature on TP-Link TL-WR841N V13 (JP) with firmware versions prior to 201216 allows authenticated users to execute arbitrary code as root via shell metacharacters, a different vulnerability than CVE-2018-12577.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:tp-link:tl-wr841n_firmware:*:*:*:*:*:*:*:* 201216 (excluding)
cpe:2.3:h:tp-link:tl-wr841n:v13:*:*:*:*:*:*:*