A command injection vulnerability exists in TP-Link WDR Series devices through firmware v3 (e.g., TL-WDR5620 V3.0). The vulnerability is present in the weather get_weather_observe functionality, where the citycode field does not properly sanitize shell metacharacters, allowing an authenticated attacker to inject arbitrary commands, resulting in remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository contains a single Python proof-of-concept exploit (poc.py) targeting a command execution vulnerability in the TP-LINK WDR5620-V3.0 router. The exploit works by sending a crafted POST request to the router's API endpoint, injecting a shell command ('whoami') via the 'citycode' parameter in the JSON body. The output of the command is redirected to a file in the router's web directory, which is then retrieved via a subsequent GET request. The script is self-contained, requires the target router to be accessible at 192.168.1.1, and assumes a valid session token (stok). The exploit demonstrates arbitrary command execution and exfiltration of results, making it a functional POC for this vulnerability. The repository is straightforward, containing only the exploit script, and does not use any external frameworks.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.