Post-Authentication Command Injection Vulnerability in TP-Link M7350 V3
CVE-2019-12104
8.8HIGH
Summary
The TP-Link M7350 V3 web-based configuration interface is susceptible to multiple command injection vulnerabilities that can be exploited once a user has been authenticated. Attackers can leverage this flaw to execute arbitrary commands on the device, compromising its integrity and potentially gaining unauthorized access to sensitive information or network resources. Users are advised to update their firmware to version 190531 or later to mitigate these vulnerabilities.
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved