Critical severity9.8NVD Advisory· Published Jan 6, 2021· Updated Jun 17, 2026
CVE-2020-36178
CVE-2020-36178
Description
oal_ipt_addBridgeIsolationRules on TP-Link TL-WR840N 6_EU_0.9.1_4.16 devices allows OS command injection because a raw string entered from the web interface (an IP address field) is used directly for a call to the system library function (for iptables). NOTE: oal_ipt_addBridgeIsolationRules is not the only function that calls util_execSystem.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- TP-Link/TL-WR840Ndescription
- cpe:2.3:o:tp-link:tl-wr840n_firmware:6_eu_0.9.1_4.16:*:*:*:*:*:*:*
Patches
Vulnerability mechanics
References
3- github.com/therealunicornsecurity/therealunicornsecurity.github.io/blob/master/_posts/2020-10-11-TPLink.mdnvdExploitThird Party Advisory
- therealunicornsecurity.github.io/TPLink/nvdExploitThird Party Advisory
- www.tp-link.com/fr/support/download/tl-wr840n/v6/nvdVendor Advisory
News mentions
0No linked articles in our index yet.