PT-2025-16890 · Tp Link · Tp-Link M7450
The Veteran
·
Published
2025-03-11
·
Updated
2025-04-24
·
CVE-2025-29653
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware version 1.0.2 Build 170306 Rel.1015n
Description
A SQL Injection vulnerability exists, allowing an unauthenticated attacker to inject malicious SQL statements via the
username and password fields. This enables the attacker to potentially access or manipulate sensitive data.Recommendations
For TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware version 1.0.2 Build 170306 Rel.1015n, consider disabling the login functionality that uses the
username and password fields until a patch is available. Restrict access to the router's administration interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.Exploit
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link M7450