router.com
http://router.com/ CVE-2022-25060
CRITICAL
TP-Link tl-wr840n_firmware Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Record summary
CVE-2022-25060 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC.
Description
TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_startPing.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · Aug 19, 2022 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
tl-wr840n_firmwareBrowse TP-Link / tl-wr840n_firmware | VulnCheck | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubexploitwritter/CVE-2022-25060Repository PoCby exploitwritterStars: 0Not analyzed3 files
References
4tp-link.com
http://tp-link.com/ east-trowel-102.notion.site
https://east-trowel-102.notion.site/CVE-2021-XXXX-Injection-of-commands-through-object-oal_startPing-EN-939c748c5f244504899477114b1ca1cf nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-25060