packetstormsecurity.com
http://packetstormsecurity.com/files/156584/TP-Link-TL-WR849N-Remote-Code-Execution.html CVE-2020-9374
CRITICAL
TP-Link tl-wr849n_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2020-9374 has a selected CVSS score of 9.8 (critical); EIP currently links 1 catalogued exploit.
Description
On TP-Link TL-WR849N 0.9.1 4.16 devices, a remote command execution vulnerability in the diagnostics area can be exploited when an attacker sends specific shell metacharacters to the panel's traceroute feature.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Mar 23, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Catalogued exploits
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tl-wr849n_firmwareBrowse TP-Link / tl-wr849n_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBTP LINK TL-WR849N - Remote Code ExecutionExploitDB exploitby Elber TavaresNot analyzed1 file
References
4fireshellsecurity.team
https://fireshellsecurity.team/hack-n-routers github.com
https://github.com/ElberTavares/routers-exploit/tree/master/tp-link nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-9374