afang5472

2 exploits Active since Jan 2019
CVE-2019-6487 NOMISEC HIGH WORKING POC
TP-Link WDR Series < 3.0 - Authenticated Remote Code Execution via Weather Citycode Field
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
40 stars
CVSS 8.8
CVE-2020-0753 NOMISEC HIGH WORKING POC
Windows Error Reporting - Privilege Escalation
An elevation of privilege vulnerability exists in Windows Error Reporting (WER) when WER handles and executes files, aka 'Windows Error Reporting Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-0754.
15 stars
CVSS 7.8