CVE-2022-25061
TP-Link TL-WR840N - Command Injection
Record summary
CVE-2022-25061 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.
Proofs of concept
1Repository PoCs
GitHubexploitwritter/CVE-2022-25061Repository PoCby exploitwritterStars: 2Not analyzed3 files
Nuclei templates
1ProjectDiscoveryCRITICALTP-Link TL-WR840N - Command InjectionCVSS 9.8
The TP-Link TL-WR840N(ES)_V6.20_180709 router contains a command injection vulnerability in the oal_setIp6DefaultRoute component. This vulnerability allows authenticated attackers to execute arbitrary system commands, leading to complete device compromise.
Impact
Authenticated attackers can inject system commands through the oal_setIp6DefaultRoute component to execute arbitrary commands on the TP-Link router, enabling complete device compromise and network infiltration.
Remediation
Update firmware to the latest version if available. If no firmware update is available,consider implementing network segmentation to limit access to the router's management interface.
Source: ProjectDiscovery