Exploitation Summary
EIP tracks 1 public exploit for CVE-2018-12692. PoCs published by yoresongo.
AI-analyzed exploit summary This exploit demonstrates a command injection vulnerability in TP-Link TL-WA850RE Wi-Fi Range Extender by injecting a command into the 'wps_setup_pin' parameter, enabling remote command execution via telnet. It authenticates using a password and cookie, then sends a crafted POST request to trigger the payload.
Description
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.
Exploits (1)
This exploit demonstrates a command injection vulnerability in TP-Link TL-WA850RE Wi-Fi Range Extender by injecting a command into the 'wps_setup_pin' parameter, enabling remote command execution via telnet. It authenticates using a password and cookie, then sends a crafted POST request to trigger the payload.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H