CVE-2025-29651

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 24, 2025
CWE ID 89

Summary

CVE-2025-29651 is a newly identified SQL Injection vulnerability affecting the TP-Link M7650 4G LTE Mobile Wi-Fi Router with Firmware Version: 1.0.7 Build 170623 Rel.1022n. This issue allows unauthenticated attackers to inject malicious SQL statements through the router's username and password fields. However, it is essential to note that the authenticity of this vulnerability is under dispute since it can only be reproduced on a supplier-provided emulator, where access control is intentionally absent for functional testing purposes.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share