TP-Link TL-WPA8630 V2.2.4 Build 20230427 Remote Code Execution Vulnerability
Vulnerability
A remote code execution vulnerability has been identified in the TP-Link TL-WPA8630 (US) version V2.2.4 Build 20230427. The issue arises from a command injection vulnerability in the function sub_4256CC, which allows attackers to execute arbitrary code by injecting specific commands.
Impact
Exploitation of this vulnerability allows for remote code execution on the affected device.
Reproduction
To reproduce this vulnerability, send a command injection payload that includes the 'devpwd' parameter to the vulnerable device running TP-Link TL-WPA8630 V2.2.4 Build 20230427. The injected command will be executed on the device, leading to remote code execution.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
