CVE-2019-12103 is a critical pre-authentication command injection vulnerability impacting the web-based configuration interface of the TP-Link M7350 V3 mobile Wi-Fi router with firmware versions prior to 190531. This flaw allows an unauthenticated attacker to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While there is no known public exploit code or active exploitation listed in KEV, the vulnerability has garnered some community discussion and media coverage, suggesting awareness within the cybersecurity landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 190531CPE matchmatch criteria | cpe:2.3:o:tp-link:m7350_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.