Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown

CVE-2023-43135

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.
Attacker Value
Unknown

CVE-2023-43138

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.
Attacker Value
Unknown

CVE-2023-43137

Disclosure Date: September 20, 2023 (last updated October 08, 2023)
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.
Attacker Value
Unknown

CVE-2017-15616

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua file.
0
Attacker Value
Unknown

CVE-2017-15622

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_client.lua file.
0
Attacker Value
Unknown

CVE-2017-15634

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.
0
Attacker Value
Unknown

CVE-2017-15617

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.
0
Attacker Value
Unknown

CVE-2017-15623

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.
0
Attacker Value
Unknown

CVE-2017-15632

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file.
0
Attacker Value
Unknown

CVE-2017-15620

Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-zone variable in the ipmac_import.lua file.
0