#VU18104 OS Command Injection in TP-Link SR20 Smart Home Router
Published: April 1, 2019
TP-Link SR20 Smart Home Router
TP-Link
Description
The vulnerability allows a remote attacker to execute arbitrary shell commands on the target system.
The vulnerability exists due to incorrect filtration of user-supplied input and absent authentication when processing TFPT requests . A remote unauthenticated attacker can send a specially crafted TFPT request to upload a file and an OS command to execute arbitrary command with root privileges on the affected device.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.