Tp-link

Tl-er5120g Firmware

7 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.09%
  • Veröffentlicht 20.09.2023 22:15:13
  • Zuletzt bearbeitet 21.11.2024 08:23:45

There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device b...

Exploit
  • EPSS 1.23%
  • Veröffentlicht 20.09.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 08:23:45

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

Exploit
  • EPSS 1.23%
  • Veröffentlicht 20.09.2023 20:15:12
  • Zuletzt bearbeitet 21.11.2024 08:23:45

TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

Exploit
  • EPSS 2.89%
  • Veröffentlicht 27.11.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function...

Exploit
  • EPSS 1.37%
  • Veröffentlicht 27.11.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 27.11.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read re...

  • EPSS 0.86%
  • Veröffentlicht 27.11.2017 10:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /u...