CVE-2025-29652
CVSS 3.1 Score 9.8 of 10 (high)
Details
Summary
CVE-2025-29652 is a newly identified SQL Injection vulnerability affecting the TP-Link M7000 4G LTE Mobile Wi-Fi Router with Firmware Version: 1.0.7 Build 180127 Rel.55998n. This issue allows unauthenticated attackers to inject malicious SQL statements through the username and password fields. However, it's important to note that the vulnerability is disputed since it can only be reproduced on a supplier-provided emulator, where access control is deliberately relaxed for functional testing purposes. The potential impact of this vulnerability includes unauthorized access, data theft, and system compromise. Users are advised to update their firmware to the latest version or contact their supplier for assistance.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.