Severity
High
Analysis Summary
CVE-2024-21827
Tp-Link ER7206 Omada Gigabit VPN Router could allow a remote authenticated attacker to execute arbitrary code on the system, caused by a leftover debug code vulnerability exists in the cli_server debug functionality. By sending specially crafted series of network requests, an attacker could exploit this vulnerability to execute arbitrary code on the system.
Impact
- Code Execution
Indicators of Compromise
CVE
- CVE-2024-21827
Affected Vendors
TP-Link
Affected Products
- Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1
Remediation
Refer to TP-Link Website for patch, upgrade or suggested workaround information.