Description
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Product status
Any version before V6_260528
Credits
Duong Ton Hoang Khang of Sacombank
References
www.tp-link.com/en/support/download/tl-wr940n/v6/
www.tp-link.com/us/support/download/tl-wr940n/v6/
www.tp-link.com/us/support/faq/5131/