TP-Link TL-WA850RE Wi-Fi Range Extender Vulnerability
CVE-2018-12692
8.8HIGH
Summary
The TP-Link TL-WA850RE Wi-Fi Range Extender, specifically version 5, is susceptible to a security vulnerability that allows remote authenticated users to execute arbitrary commands. This is made possible through crafted shell metacharacters included in the wps_setup_pin parameter when sending requests to /data/wps.setup.json. This weakness can potentially be exploited to gain unauthorized control over the device, leading to serious security breaches.
References
EPSS Score
7% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability Reserved
Vulnerability published