Vulnerabilities > TP Link
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2018-05-03 | CVE-2018-10166 | Cross-Site Request Forgery (CSRF) vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0 The web management interface in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows does not have Anti-CSRF tokens in any forms. | 8.8 |
2018-05-03 | CVE-2018-10165 | Cross-site Scripting vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0 Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the userName parameter in the local user creation functionality. | 5.4 |
2018-05-03 | CVE-2018-10164 | Cross-site Scripting vulnerability in Tp-Link EAP Controller 2.5.4/2.6.0 Stored Cross-site scripting (XSS) vulnerability in the TP-Link EAP Controller and Omada Controller versions 2.5.4_Windows/2.6.0_Windows allows authenticated attackers to inject arbitrary web script or HTML via the implementation of portalPictureUpload functionality. | 5.4 |
2018-01-11 | CVE-2017-15637 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_server.lua file. | 7.2 |
2018-01-11 | CVE-2017-15636 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-time variable in the webfilter.lua file. | 7.2 |
2018-01-11 | CVE-2017-15635 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the max_conn variable in the session_limits.lua file. | 7.2 |
2018-01-11 | CVE-2017-15634 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the name variable in the wportal.lua file. | 7.2 |
2018-01-11 | CVE-2017-15633 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-ipgroup variable in the session_limits.lua file. | 7.2 |
2018-01-11 | CVE-2017-15632 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-mppeencryption variable in the pptp_server.lua file. | 7.2 |
2018-01-11 | CVE-2017-15631 | Unspecified vulnerability in Tp-Link products TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file. | 7.2 |