TP-Link M7000 4G LTE Mobile Wi-Fi Router SQL Injection Vulnerability

Vulnerability

A SQL injection vulnerability has been identified in the TP-Link M7000 4G LTE Mobile Wi-Fi Router, specifically in Firmware Version 1.0.7 Build 180127 Rel.55998n. This vulnerability allows an unauthenticated attacker to inject malicious SQL statements through the username and password fields. However, it is important to note that this issue can only be reproduced on a supplier-provided emulator, where access control is intentionally absent to facilitate functional testing.

Impact

Exploitation of this vulnerability allows for SQL injection, where an attacker can manipulate SQL queries to the database. This could potentially lead to unauthorized data access, data manipulation, or in some cases, executing administrative operations on the database.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
3.1
exploitability
7.4
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.