Description
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authenticated attacker with administrative privileges may be able to execute arbitrary commands when applying configuration changes.Successful exploitation may result in a full compromise of confidentiality, integrity, and availability of the affected device.
Problem types
CWE-78 Improper neutralization of special elements used in an OS command ('OS command injection')
Product status
Any version before EU_V5_1.7.0 0.9.1 260518 rel67803
Any version before JP_V5_1.2.0 0.9.1 260519 rel52362
Credits
Akira Moroo (Ricerca Security, Inc.), Satoki Tsuji (Ricerca Security, Inc.), Anonymous
References
www.tp-link.com/en/support/download/archer-mr600/v5/
www.tp-link.com/jp/support/download/archer-mr600/v5/
www.tp-link.com/us/support/faq/5122/