High severity8.8NVD Advisory· Published May 30, 2018· Updated Jun 17, 2026
CVE-2018-11481
CVE-2018-11481
Description
TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices allow authenticated remote code execution via crafted JSON data because /usr/lib/lua/luci/torchlight/validator.lua does not block various punctuation characters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- cpe:2.3:o:tp-link:ipc_tl-ipc223\(p\)-6_firmware:*:*:*:*:*:*:*:*Range: <1.0.21
- cpe:2.3:o:tp-link:tl-ipc325\(kp\)_firmware:*:*:*:*:*:*:*:*Range: <1.0.21
Patches
Vulnerability mechanics
References
1- github.com/yough3rt/IOT-pwn-for-fun/blob/master/TP-LINK-websys-Authenticated-RCEnvdThird Party Advisory
News mentions
0No linked articles in our index yet.