The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field.
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Link | Tags |
---|---|
http://tp-link.com | vendor advisory |
https://www.tp-link.com/us/press/security-advisory/ | vendor advisory |
https://k4m1ll0.com/cve-2021-41653.html | third party advisory exploit |