VYPR

Tl Er5120g Firmware

by TP-Link

CVEs (7)

  • CVE-2023-43135CriSep 20, 2023
    risk 0.64cvss 9.8epss 0.01

    There is an unauthorized access vulnerability in TP-LINK ER5120G 4.0 2.0.0 Build 210817 Rel.80868n, which allows attackers to obtain sensitive information of the device without authentication, obtain user tokens, and ultimately log in to the device backend management.

  • CVE-2017-16957HigNov 27, 2017
    risk 0.58cvss 8.8epss 0.06

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in…

  • CVE-2023-43138HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds NAPT rules after authentication, and the rule name has an injection point.

  • CVE-2023-43137HigSep 20, 2023
    risk 0.57cvss 8.8epss 0.02

    TPLINK TL-ER5120G 4.0 2.0.0 Build 210817 Rel.80868n has a command injection vulnerability, when an attacker adds ACL rules after authentication, and the rule name parameter has injection points.

  • CVE-2017-16960HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.02

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in…

  • CVE-2017-16958HigNov 27, 2017
    risk 0.57cvss 8.8epss 0.03

    TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in…

  • CVE-2017-16959MedNov 27, 2017
    risk 0.42cvss 6.5epss 0.02

    The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request with a crafted…