The web-based configuration interface of the TP-Link M7350 V3 with firmware before 190531 is affected by a pre-authentication command injection vulnerability.
No PoCs from references.
- https://github.com/attilaszia/linux-iot-cves
- https://github.com/geeksniper/reverse-engineering-toolkit