HIGH🇵🇱 Wersja polska

CVE-2018-12692

CVSS 8.8v3.0pub. 2018-06-23upd. 2024-11-21

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.setup.json.

CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Tp Link Tl Wa850re

    HW
    Tp-Link
    5
  • Tp Link Tl Wa850re Firmware

    OS
    Tp-Link
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2022-22922CRITICAL9.8PL ✓same product

Przewidywalne klucze sesji w TP-Link TL-WA850RE umożliwiają przejęcie uprawnień administratora

CVE-2025-14737HIGH7.1same product

Command Injection vulnerability in TP-Link WA850RE (httpd modules) allows authenticated adjacent attacker to i...

CVE-2018-12694HIGH7.5same product

TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of s...

CVE-2025-14738MEDIUM5.7same product

Luka w uwierzytelnianiu w TP-Link WA850RE (moduły httpd) pozwala nieuwierzytelnionym ataczkownikom pobrać plik...

CVE-2018-12693MEDIUM6.5same product

Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote a...