TP-Link wifi router TL-WR802N V4(JP), with firmware version prior to 211202, is vulnerable to OS command injection.
The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.
Link | Tags |
---|---|
https://www.tp-link.com/jp/support/download/tl-wr802n/#Firmware | product vendor advisory |
https://jvn.jp/en/vu/JVNVU94883311/ | vdb entry third party advisory |