Multiple TP-LINK products allow a network-adjacent...
Moderate severity
Unreviewed
Published
Jul 4, 2024
to the GitHub Advisory Database
•
Updated Mar 13, 2025
Description
Published by the National Vulnerability Database
Jul 4, 2024
Published to the GitHub Advisory Database
Jul 4, 2024
Last updated
Mar 13, 2025
Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
References