TP-Link EAP120 Router SQL Injection Vulnerability in Login Dashboard

Vulnerability

A SQL injection vulnerability has been identified in the TP-Link EAP120 router's login dashboard, version 1.0. This vulnerability allows an unauthenticated attacker to inject malicious SQL statements through the login fields. However, it is important to note that this issue can only be reproduced on a supplier-provided emulator, where access control is intentionally disabled for functional testing.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate SQL queries to the database. This could potentially lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.