Post-Authentication Command Injection Vulnerability in TP-Link M7350 V3
CVE-2019-12104

8.8HIGH

Key Information:

Vendor
Tp-link
Vendor
CVE Published:
14 August 2019

Summary

The TP-Link M7350 V3 web-based configuration interface is susceptible to multiple command injection vulnerabilities that can be exploited once a user has been authenticated. Attackers can leverage this flaw to execute arbitrary commands on the device, compromising its integrity and potentially gaining unauthorized access to sensitive information or network resources. Users are advised to update their firmware to version 190531 or later to mitigate these vulnerabilities.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.