TP-Link Vulnerabilities and Affected Products
Vulnerabilities associated with ER7206 Omada Gigabit VPN Router.
Products
Clear product- tl-wr886n_firmware14 vulnerabilities
- AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)12 vulnerabilities
- ac1350_firmware11 vulnerabilities
- N300 Wireless Access Point (EAP115)10 vulnerabilities
- n300_firmware10 vulnerabilities
- Archer A79 vulnerabilities
- ER7206 Omada Gigabit VPN Router9 vulnerabilities
- TL-WR841N8 vulnerabilities
- TL-WR940N8 vulnerabilities
- Omada ER6057 vulnerabilities
- tl-wdr7660_firmware6 vulnerabilities
- tl-wr941nd5 vulnerabilities
- AC17504 vulnerabilities
- Archer AX30004 vulnerabilities
- Archer AX54004 vulnerabilities
- tl-wr840n_firmware4 vulnerabilities
- VN020 F3v(T)4 vulnerabilities
- Archer Air R53 vulnerabilities
- Archer AX213 vulnerabilities
- Archer AXE753 vulnerabilities
- Archer C53 vulnerabilities
- Archer C503 vulnerabilities
- TL-WR902AC3 vulnerabilities
- tl-wr902ac_firmware3 vulnerabilities
- TP-Link TL-WRN841N3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-21827HIGH | A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. CWE-489Jun 25, 2024 | CVSS7.2v3.1 | EPSS0.871% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-43482HIGH | A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.25% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-36498HIGH | A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47209HIGH | A post authentication command injection vulnerability exists in the ipsec policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47167HIGH | A post authentication command injection vulnerability exists in the GRE policy functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-42664HIGH | A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-46683HIGH | A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47617HIGH | A post authentication command injection vulnerability exists when configuring the web group member of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS3.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2023-47618HIGH | A post authentication command execution vulnerability exists in the web filtering functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability. CWE-78Feb 6, 2024 | CVSS7.2v3.1 | EPSS1.94% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |