Show filters
32 Total Results
Displaying 1-10 of 32
Sort by:
Attacker Value
Unknown
CVE-2023-43135
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.
0
Attacker Value
Unknown
CVE-2023-43138
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.
0
Attacker Value
Unknown
CVE-2023-43137
Disclosure Date: September 20, 2023 (last updated October 08, 2023)
TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.
0
Attacker Value
Unknown
CVE-2017-15616
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-interface variable in the phddns.lua file.
0
Attacker Value
Unknown
CVE-2017-15622
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_client.lua file.
0
Attacker Value
Unknown
CVE-2017-15634
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file.
0
Attacker Value
Unknown
CVE-2017-15617
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.
0
Attacker Value
Unknown
CVE-2017-15623
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.
0
Attacker Value
Unknown
CVE-2017-15632
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file.
0
Attacker Value
Unknown
CVE-2017-15620
Disclosure Date: January 11, 2018 (last updated November 26, 2024)
TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-zone variable in the ipmac_import.lua file.
0