PT-2022-4968 · Tp Link · Tp-Link M7350

Published

2022-09-12

·

Updated

2023-08-08

·

CVE-2022-37860

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link M7350 version 190531
Description The web configuration interface of the TP-Link M7350 is affected by a pre-authentication command injection issue. This is related to the lack of data cleaning measures at the management level. Exploitation of this issue may allow a remote attacker to execute arbitrary commands.
Recommendations For version 190531, consider disabling remote access to the web configuration interface until a patch is available. Restrict access to the vulnerable interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Exploit

Fix

OS Command Injection

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-06162
CVE-2022-37860

Affected Products

Tp-Link M7350