Multiple TP-LINK products allow a network-adjacent attacker with an administrative privilege to execute arbitrary OS commands by restoring a crafted backup file. The affected device, with the initial configuration, allows login only from the LAN port or Wi-Fi.
References
Configurations
No configuration.
History
13 Mar 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-78 |
Information
Published : 2024-07-04 01:15
Updated : 2025-03-13 14:15
NVD link : CVE-2024-38471
Mitre link : CVE-2024-38471
CVE.ORG link : CVE-2024-38471
JSON object : View
Products Affected
No product.
CWE
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')