An arbitrary OS command may be executed on the product by a remote unauthenticated attacker.
An attacker sends a specially crafted network request to the vulnerable device without needing any authentication credentials. The injected command (command injection) is then executed by the device's operating system with the privileges of the process handling the request. The vulnerability results from insufficient validation or sanitization of input data passed to system functions, classifying it as CWE-78 (Improper Neutralization of Special Elements used in an OS Command).
An attacker can execute arbitrary commands at the operating system level on the device, which in practice means complete takeover of the router — including the ability to change network configuration, intercept network traffic, install backdoors, and use the device as an entry point to the internal network.
Patches available from the manufacturer must be applied immediately in accordance with the document published at https://support.omadanetworks.com/en/document/108455/. Additionally, it is recommended to restrict access to the device management interface only to trusted IP addresses and prevent exposure of the administrative panel to untrusted networks (e.g., the Internet).
TP-Link devices: FR307-M2 (firmware), G36, ER707-M2, ER706W (firmware), ER7206 (firmware) — specific versions of vulnerable software indicated in the manufacturer's references.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XTp Link Er605
HWTp-Linkall versionsTp Link Er605 Firmware
OSTp-Link2.3.1< 2.3.1Tp Link Er706w
HWTp-Linkall versionsTp Link Er706w 4g
HWTp-Linkall versionsTp Link Er706w 4g Firmware
OSTp-Link1.2.1< 1.2.1Tp Link Er706w Firmware
OSTp-Link1.2.1< 1.2.1Tp Link Er707 M2
HWTp-Linkall versionsTp Link Er707 M2 Firmware
OSTp-Link1.3.1< 1.3.1Tp Link Er7206
HWTp-Linkall versionsTp Link Er7206 Firmware
OSTp-Link2.2.2< 2.2.2Tp Link Er7212pc
HWTp-Linkall versionsTp Link Er7212pc Firmware
OSTp-Link2.1.3< 2.1.3Tp Link Er7412 M2
HWTp-Linkall versionsTp Link Er7412 M2 Firmware
OSTp-Link1.1.0< 1.1.0Tp Link Er8411
HWTp-Linkall versionsTp Link Er8411 Firmware
OSTp-Link1.3.3< 1.3.3Tp Link Fr205
HWTp-Linkall versionsTp Link Fr205 Firmware
OSTp-Link1.0.3< 1.0.3Tp Link Fr307 M2
HWTp-Linkall versionsTp Link Fr307 M2 Firmware
OSTp-Link1.2.5< 1.2.5Tp Link Fr365
HWTp-Linkall versionsTp Link Fr365 Firmware
OSTp-Link1.1.10< 1.1.10Tp Link G36
HWTp-Linkall versionsTp Link G36 Firmware
OSTp-Link1.1.4< 1.1.4Tp Link G611
HWTp-Linkall versionsTp Link G611 Firmware
OSTp-Link1.2.2< 1.2.2
Related vulnerabilities
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to op...
Command injection w bramkach Omada (TP-Link) po uwierzytelnieniu admina
An attacker may obtain the root shell on the underlying OS system with the restricted conditions on Omada gate...
An arbitrary OS command may be executed on the product by the user who can log in to the web management interf...
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigab...