CVE-2020-36178
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables).
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (9.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 9.70% probability · 95th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-78
- Affected
- tp-link/tl-wr840n firmware
- Source
- cve@mitre.org
References
- https://github.com/therealunicornsecurity/therealunicornsecurity.github.io/blob/master/_posts/2020-10-11-TPLink.mdExploit, Third Party Advisory
- https://therealunicornsecurity.github.io/TPLink/Exploit, Third Party Advisory
- https://www.tp-link.com/fr/support/download/tl-wr840n/v6/#FirmwareVendor Advisory
- https://github.com/therealunicornsecurity/therealunicornsecurity.github.io/blob/master/_posts/2020-10-11-TPLink.mdExploit, Third Party Advisory
- https://therealunicornsecurity.github.io/TPLink/Exploit, Third Party Advisory
- https://www.tp-link.com/fr/support/download/tl-wr840n/v6/#FirmwareVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.