There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2022-03-04T21:27:48
Updated: 2024-08-04T04:32:13.206Z
Reserved: 2021-12-11T00:00:00
Link: CVE-2021-44827
Vulnrichment
No data.
NVD
Status : Modified
Published: 2022-03-04T22:15:19.193
Modified: 2024-11-21T06:31:34.293
Link: CVE-2021-44827
Redhat
No data.