Show filters
400 Total Results
Displaying 61-70 of 400
Sort by:
Attacker Value
Unknown

CVE-2023-46683

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
A post authentication command injection vulnerability exists when configuring the wireguard VPN functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection . An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-43482

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
A command execution vulnerability exists in the guest resource functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-42664

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
A post authentication command injection vulnerability exists when setting up the PPTP global configuration of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability.
Attacker Value
Unknown

CVE-2023-36498

Disclosure Date: February 06, 2024 (last updated February 09, 2024)
A post-authentication command injection vulnerability exists in the PPTP client functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.3.0 build 20230322 Rel.70591. A specially crafted HTTP request can lead to arbitrary command injection. An attacker can make an authenticated HTTP request to trigger this vulnerability and gain access to an unrestricted shell.
Attacker Value
Unknown

CVE-2023-49515

Disclosure Date: January 17, 2024 (last updated January 25, 2024)
Insecure Permissiosn vulnerability in TP Link TC70 and C200 WIFI Camera v.3 firmware v.1.3.4 and fixed in v.1.3.11 allows a physically proximate attacker to obtain sensitive information via a connection to the UART pin components.
Attacker Value
Unknown

CVE-2024-21833

Disclosure Date: January 11, 2024 (last updated July 04, 2024)
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product to execute arbitrary OS commands. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
Attacker Value
Unknown

CVE-2024-21821

Disclosure Date: January 11, 2024 (last updated July 04, 2024)
Multiple TP-LINK products allow a network-adjacent authenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands.
Attacker Value
Unknown

CVE-2024-21773

Disclosure Date: January 11, 2024 (last updated July 04, 2024)
Multiple TP-LINK products allow a network-adjacent unauthenticated attacker with access to the product from the LAN port or Wi-Fi to execute arbitrary OS commands on the product that has pre-specified target devices and blocked URLs in parental control settings.
Attacker Value
Unknown

CVE-2023-27098

Disclosure Date: January 09, 2024 (last updated January 13, 2024)
TP-Link Tapo APK up to v2.12.703 uses hardcoded credentials for access to the login panel.
Attacker Value
Unknown

CVE-2023-34829

Disclosure Date: December 28, 2023 (last updated January 06, 2024)
Incorrect access control in TP-Link Tapo before v3.1.315 allows attackers to access user credentials in plaintext.