CVE-2025-29652

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Apr 16, 2025
Updated: Apr 24, 2025
CWE ID 89

Summary

CVE-2025-29652 is a newly identified SQL Injection vulnerability affecting the TP-Link M7000 4G LTE Mobile Wi-Fi Router with Firmware Version: 1.0.7 Build 180127 Rel.55998n. This issue allows unauthenticated attackers to inject malicious SQL statements through the username and password fields. However, it's important to note that the vulnerability is disputed since it can only be reproduced on a supplier-provided emulator, where access control is deliberately relaxed for functional testing purposes. The potential impact of this vulnerability includes unauthorized access, data theft, and system compromise. Users are advised to update their firmware to the latest version or contact their supplier for assistance.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share