CVE-2022-25060
CRITICAL EXPLOITED IN THE WILDTP-LINK TL-WR840N(ES)_V6.20_180709 - OS Command Injection via oal_startPing
Title source: llmExploitation Summary
CVE-2022-25060 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including exploitwritter.
AI-analyzed exploit summary This exploit targets a remote command execution vulnerability in the TPLink WR840N router's oal_startPing component. It leverages a command injection flaw to download and execute a reverse shell payload via TFTP.
Description
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Exploits (1)
This exploit targets a remote command execution vulnerability in the TPLink WR840N router's oal_startPing component. It leverages a command injection flaw to download and execute a reverse shell payload via TFTP.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H