PT-2022-11574 · Tp Link · Tp-Link Archer A7

Published

2022-08-23

·

Updated

2022-08-25

·

CVE-2021-42232

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Archer A7 version Archer A7(US) V5 210519
Description The issue is caused by a command injection vulnerability in the /usr/bin/tddp program, which takes part of the received data packet as part of the command. This allows an attacker to execute arbitrary commands on the router.
Recommendations For TP-Link Archer A7 version Archer A7(US) V5 210519, consider disabling the /usr/bin/tddp program until a patch is available to prevent exploitation of the command injection vulnerability.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-42232

Affected Products

Tp-Link Archer A7