Vulnerability Description
The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr840N Firmware | <= 0.9.1_3.16 |
| Tp-Link | Tl-Wr840N | - |
Related Weaknesses (CWE)
References
- https://twitter.com/rapt00rvfThird Party Advisory
- https://vitor-fernandes.github.io/First-CVE/ExploitThird Party Advisory
- https://twitter.com/rapt00rvfThird Party Advisory
- https://vitor-fernandes.github.io/First-CVE/ExploitThird Party Advisory
FAQ
What is CVE-2019-15060?
CVE-2019-15060 is a vulnerability with a CVSS score of 8.8 (HIGH). The traceroute function on the TP-Link TL-WR840N v4 router with firmware through 0.9.1 3.16 is vulnerable to remote code execution via a crafted payload in an IP address input field.
How severe is CVE-2019-15060?
CVE-2019-15060 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-15060?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr840N Firmware, Tp-Link Tl-Wr840N.