CVE-2024-21827

A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:er7206_firmware:1.4.1:build_20240117_rel_57421:*:*:*:*:*:*
cpe:2.3:h:tp-link:er7206:-:*:*:*:*:*:*:*

History

05 Sep 2025, 15:50

Type Values Removed Values Added
First Time Tp-link
Tp-link er7206 Firmware
Tp-link er7206
CPE cpe:2.3:h:tp-link:er7206:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:er7206_firmware:1.4.1:build_20240117_rel_57421:*:*:*:*:*:*
References () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1947 - () https://talosintelligence.com/vulnerability_reports/TALOS-2024-1947 - Exploit, Third Party Advisory

Information

Published : 2024-06-25 14:15

Updated : 2025-09-05 15:50


NVD link : CVE-2024-21827

Mitre link : CVE-2024-21827

CVE.ORG link : CVE-2024-21827


JSON object : View

Products Affected

tp-link

  • er7206_firmware
  • er7206
CWE
CWE-489

Active Debug Code