CVE-2021-37774

An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.
References
Link Resource
https://github.com/fishykz/TP-POC Exploit Third Party Advisory
https://github.com/fishykz/TP-POC Exploit Third Party Advisory
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7660_firmware:2.0.30:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7660:-:*:*:*:*:*:*:*

History

04 Apr 2025, 16:15

Type Values Removed Values Added
CWE CWE-94

Information

Published : 2023-01-19 13:15

Updated : 2025-04-04 16:15


NVD link : CVE-2021-37774

Mitre link : CVE-2021-37774

CVE.ORG link : CVE-2021-37774


JSON object : View

Products Affected

tp-link

  • tl-wdr7660_firmware
  • tl-wdr7660
CWE
NVD-CWE-noinfo CWE-94

Improper Control of Generation of Code ('Code Injection')