CVE-2020-28347
Published
CVSS v3
9.8
CRITICAL
CVSS v2
10
HIGH
Affected
3
PROJECTS
Description
tdpServer on TP-Link Archer A7 AC1750 devices before 201029 allows remote attackers to execute arbitrary code via the slave_mac parameter. NOTE: this issue exists because of an incomplete fix for CVE-2020-10882 in which shell quotes are mishandled.
Advisories, proof of concept files and exploits that have been made public by @pedrib.
Repository that tracks public exploits, vulnerabilities and advisories that I [co-]discovered or [co-]authored.