.. / CVE-2021-41653

Exploit for TP-Link - OS Command Injection (CVE-2021-41653)

Description:

The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a specially crafted payload in an IP address input field.

Nuclei Template

View the template here CVE-2021-41653.yaml

Validate with Nuclei

echo "$URL" | nuclei -t ~/nuclei-templates/http/cves/2021/CVE-2021-41653.yaml
Copy

References:

https://github.com/ARPSyndicate/cvemon
https://nvd.nist.gov/vuln/detail/CVE-2021-41653
http://tp-link.com
https://k4m1ll0.com/cve-2021-41653.html
https://www.tp-link.com/us/press/security-advisory/