Description
A command injection vulnerability exists that can be exploited after authentication in VIGI NVR1104H-4P V1 and VIGI NVR2016H-16MP V2.This issue affects VIGI NVR1104H-4P V1: before 1.1.5 Build 250518; VIGI NVR2016H-16MP V2: before 1.3.1 Build 250407.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version before 1.1.5 Build 250518
Any version before 1.3.1 Build 250407
References
www.tp-link.com/us/support/faq/4547/
www.tp-link.com/jp/support/download/vigi-nvr1104h-4p/
www.tp-link.com/jp/support/download/vigi-nvr2016h-16mp/