Record summary

CVE-2022-25061 has a selected CVSS score of 9.8 (critical); EIP currently links 1 repository PoC and 1 Nuclei template.

Description

TP-LINK TL-WR840N(ES)_V6.20_180709 was discovered to contain a command injection vulnerability via the component oal_setIp6DefaultRoute.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
1
Nuclei templates
1

Proofs of concept

1

Repository PoCs

GitHubexploitwritter/CVE-2022-25061Repository PoCby exploitwritterStars: 2Not analyzed3 files

5.4 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryCRITICALTP-Link TL-WR840N - Command InjectionCVSS 9.8

The TP-Link TL-WR840N(ES)_V6.20_180709 router contains a command injection vulnerability in the oal_setIp6DefaultRoute component. This vulnerability allows authenticated attackers to execute arbitrary system commands, leading to complete device compromise.

Impact

Authenticated attackers can inject system commands through the oal_setIp6DefaultRoute component to execute arbitrary commands on the TP-Link router, enabling complete device compromise and network infiltration.

Remediation

Update firmware to the latest version if available. If no firmware update is available,consider implementing network segmentation to limit access to the router's management interface.

WeaknessesCWE-78
Authorsritikchaddha
Template tagscvecve2022tplinkrouterrceiotauthenticatedvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:tp-link:tl-wr840n_firmware:6.20_180709:*:*:*:*:*:*:*
Shodan: title:"TL-WR840N"

Source: ProjectDiscovery

References

4