CVE-2025-29648
CVSS 3.1 Score 7.3 of 10 (high)
Details
Published Apr 16, 2025
Updated: Apr 24, 2025
CWE ID 89
Summary
CVE-2025-29648 is a newly discovered SQL Injection vulnerability affecting the TP-Link EAP120 router's login dashboard, specifically in version 1.0. This issue permits unauthenticated attackers to inject malicious SQL statements into the login fields. However, it is important to note that the veracity of this vulnerability is disputed, as it has only been reproduced on a supplier-provided emulator, where access control is intentionally weakened for functional testing purposes.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.