SQL Injection Flaw in TP-Link M7200 4G LTE Mobile Wi-Fi Router
CVE-2025-29650

Currently unrated

Key Information:

Vendor
TP-Link
Vendor
CVE Published:
16 April 2025

Summary

An SQL injection vulnerability has been identified in the TP-Link M7200 4G LTE Mobile Wi-Fi Router, specifically in firmware version 1.0.7 Build 180127 Rel.55998n. This flaw permits unauthenticated attackers to manipulate SQL queries by injecting malicious SQL statements through the username and password field inputs, posing significant risks to user data and the router's overall security. Proper incident response and patching are essential to mitigate these risks.

References

Timeline

  • Vulnerability published

.