PT-2025-16890 · Tp Link · Tp-Link M7450

The Veteran

·

Published

2025-03-11

·

Updated

2025-04-24

·

CVE-2025-29653

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware version 1.0.2 Build 170306 Rel.1015n
Description A SQL Injection vulnerability exists, allowing an unauthenticated attacker to inject malicious SQL statements via the username and password fields. This enables the attacker to potentially access or manipulate sensitive data.
Recommendations For TP-Link M7450 4G LTE Mobile Wi-Fi Router Firmware version 1.0.2 Build 170306 Rel.1015n, consider disabling the login functionality that uses the username and password fields until a patch is available. Restrict access to the router's administration interface to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

SQL injection

Weakness Enumeration

Related Identifiers

BDU:2025-05273
CVE-2025-29653

Affected Products

Tp-Link M7450