CVE-2024-21827
HIGHDescription
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability.
Is your site exposed to CVE-2024-21827?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| tp-link | er7206_firmware |
| tp-link | er7206 |
References
Frequently Asked Questions
What is CVE-2024-21827? +
How severe is CVE-2024-21827? +
What products are affected by CVE-2024-21827? +
How do I check if I'm vulnerable to CVE-2024-21827? +
Related Vulnerabilities
An authenticated admin user with access to both the management WebUI and command line interface on a Firebox can enable …
A vulnerability exists in serial device servers where active debug code remains enabled in the UART interface. An attacker with …
Hard-coded credentials for the CyberPower PowerPanel test server can be found in the production code. This might result in an …
Multiple SHARP routers leave the hidden debug function enabled. An arbitrary OS command may be executed with the root privilege …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to authentication bypass due to hard-coded credentials in the administrative web …
The Four-Faith F3x36 router using firmware v2.0.0 is vulnerable to an authentication bypass vulnerability in the administrative web server. Authentication …