oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2024-08-04T17:23:09.407Z

Reserved: 2021-01-06T00:00:00

Link: CVE-2020-36178

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-01-06T21:15:14.317

Modified: 2024-11-21T05:28:54.057

Link: CVE-2020-36178

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses