Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2019-6487

EPSS 24.93% · P96
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2019-6487

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
TP-Link WDR Series devices through firmware v3 (such as TL-WDR5620 V3.0) are affected by command injection (after login) leading to remote code execution, because shell metacharacters can be included in the weather get_weather_observe citycode field.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
TP-Link WDR Series 操作系统命令注入漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
TP-Link WDR Series是中国普联(TP-Link)公司的一款WDR系列无线路由器。 使用v3版本固件(例如:TL-WDR5620 V3.0版本)的TP-Link WDR Series中存在操作系统命令注入漏洞,该漏洞源于‘citycode’字段中包含了sehll元字符。远程攻击者可利用该漏洞执行代码。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
-n/a n/a -

II. Public POCs for CVE-2019-6487

#POC DescriptionSource LinkShenlong Link
1CVE-2019-6487. A command injection vulnerability in TP-Link WDR5620 Series up to verion 3.https://github.com/afang5472/TP-Link-WDR-Router-Command-injection_POCPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2019-6487

登录查看更多情报信息。

Same Patch Batch · n/a · 2019-01-18 · 99 CVEs total

CVE-2018-16038Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16032Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16028Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16027Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16026Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16025Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16024Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16029Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16036Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16037Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16035Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16039Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16040Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16041Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16042Adobe Reader 数据伪造问题漏洞
CVE-2018-16043Adobe Acrobat和Reader 缓冲区错误漏洞
CVE-2018-16044Adobe Acrobat和Reader 权限许可和访问控制问题漏洞
CVE-2018-16045Adobe Acrobat和Reader 权限许可和访问控制问题漏洞
CVE-2018-16046Adobe Acrobat和Reader 资源管理错误漏洞
CVE-2018-16047Adobe Acrobat和Reader 缓冲区错误漏洞

Showing top 20 of 99 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2019-6487

No comments yet


Leave a comment