SQL Injection Flaw in TP-Link M7200 4G LTE Mobile Wi-Fi Router
CVE-2025-29650
Currently unrated
Summary
An SQL injection vulnerability has been identified in the TP-Link M7200 4G LTE Mobile Wi-Fi Router, specifically in firmware version 1.0.7 Build 180127 Rel.55998n. This flaw permits unauthenticated attackers to manipulate SQL queries by injecting malicious SQL statements through the username and password field inputs, posing significant risks to user data and the router's overall security. Proper incident response and patching are essential to mitigate these risks.
References
Timeline
Vulnerability published