PT-2021-5665 · Tp Link · Tp-Link Tl-Wr802N

Koh You Liang

·

Published

2021-12-23

·

Updated

2022-01-04

·

CVE-2021-4144

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link wifi router TL-WR802N V4(JP) versions prior to 211202
Description The issue exists due to the lack of measures to neutralize special elements used in the operating system command. This can allow a remote attacker to execute arbitrary commands. The estimated number of potentially affected devices worldwide is not specified. There is no information about real-world incidents where this issue was exploited.
Recommendations For TP-Link wifi router TL-WR802N V4(JP) versions prior to 211202, update the firmware to version 211202 or later to resolve the issue. As a temporary workaround, consider restricting access to the router's operating system commands until a patch is available.

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-00104
CVE-2021-4144

Affected Products

Tp-Link Tl-Wr802N