PT-2024-8637 · Tp Link · Tp-Link Tl-Ipc42C

Published

2024-11-21

·

Updated

2024-11-26

·

CVE-2024-48288

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link TL-IPC42C version V4.0 20211227 1.0.16
Description The issue is related to command injection due to the lack of malicious code verification on both the frontend and backend. This allows a remote attacker to execute arbitrary code by sending specially crafted HTTP packets.
Recommendations For TP-Link TL-IPC42C version V4.0 20211227 1.0.16, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-10228
CVE-2024-48288

Affected Products

Tp-Link Tl-Ipc42C