CRITICAL
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter
Published Nov 8, 2020
9.8
CRITICALCVSS 3.1
EPSS 75.41%
Description
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
Affected products
No data.
AND
- < 201029
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-20809 Advisory
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2019/lao_bomb/lao_bomb.md x_refsource_MISCExploitThird Party Advisory
- https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/minesweeper.md x_refsource_MISCExploitThird Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/14365 x_refsource_MISCExploitPatchThird Party Advisory
- https://github.com/rdomanski/Exploits_and_Advisories/blob/master/advisories/Pwn2Own/Tokyo2019/lao_bomb.md x_refsource_MISCExploitThird Party Advisory
- https://github.com/rdomanski/Exploits_and_Advisories/blob/master/advisories/Pwn2Own/Tokyo2020/minesweeper.md x_refsource_MISCExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-20809 | Advisory | |
| https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2019/lao_bomb/lao_bomb.md | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/pedrib/PoC/blob/master/advisories/Pwn2Own/Tokyo_2020/minesweeper.md | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/rapid7/metasploit-framework/pull/14365 | x_refsource_MISCExploitPatchThird Party Advisory | |
| https://github.com/rdomanski/Exploits_and_Advisories/blob/master/advisories/Pwn2Own/Tokyo2019/lao_bomb.md | x_refsource_MISCExploitThird Party Advisory | |
| https://github.com/rdomanski/Exploits_and_Advisories/blob/master/advisories/Pwn2Own/Tokyo2020/minesweeper.md | x_refsource_MISCExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Nov 8, 2020
Updated Aug 4, 2024
Reserved Nov 8, 2020
Link CVE-2020-28347
CISA Vulnrichment
No data
Red Hat
No data
GitHub
No data