TP-Link SR20 Router Vulnerability Disclosed by Google Researcher After No Response From Company

Advertisement
By Tasneem Akolawala | Updated: 29 March 2019 14:16 IST
Highlights
  • Google researcher told TP-Link of this issue in December
  • He got no response from the company, his tweet was also ignored
  • He then published the TP-Link SR20 router vulnerability online
TP-Link SR20 Router Vulnerability Disclosed by Google Researcher After No Response From Company

TP-Link vulnerability exposes type 1 commands for attackers to exploit

According to Google security researcher Matthew Garrett, TP-Link's SR20 Smart Home Router comes with a vulnerability that allows arbitrary command execution from a local network connection. This exploit was disclosed by the researcher after he was unable to solicit a response from TP-Link, and even published a proof-of-concept to demonstrate the vulnerability. The router, which was launched in 2016, exposes a number of commands that come with root privileges and does not even require authentication. Garrett disclosed the proof-of-concept, after waiting for the Google Project Zero team's 90-day deadline for disclosure to elapse.

Garrett took to Twitter to explain that the TP Link SR20 Smart Home Router comes with TDDP (TP-Link Device Debug Protocol), which is affected with several vulnerabilities, and one of them is that version 1 commands are exposed for attackers to exploit.

He says that these exposed commands allow attackers to send a command containing a filename, a semicolon, to execute the process. “This connects back to the machine that sent the command and attempts to download a file via TFTP (Trivial File Transfer Protocol) corresponding to the filename it sent. The main TDDP process waits up to four seconds for the file to appear - once it does, it loads the file into a Lua interpreter it initialised earlier, and calls the function config_test() with the name of the config file and the remote address as arguments. Since config_test() is provided by the file that was downloaded from the remote machine, this gives arbitrary code execution in the interpreter, which includes the os.execute method which just runs commands on the host. Since TDDP is running as root, you get arbitrary command execution as root,” he explains on the blog.

This process allows for full takeover of the SR20 router. Garett says he reported to TP-Link of this vulnerability in December, via its security disclosure form. The page told him that he would get a response within three days, but hasn't heard back from them till date. He also said that he tweeted at TP-Link regarding the matter, but that garnered no response either.

Advertisement

He ends by suggesting to the company, “Don't default to running debug daemons on production firmware”, and, “If you're going to have a security disclosure form, read it.”

 

For the latest tech news and reviews, follow Gadgets 360 on X, Facebook, WhatsApp, Threads and Google News. For the latest videos on gadgets and tech, subscribe to our YouTube channel. If you want to know everything about top influencers, follow our in-house Who'sThat360 on Instagram and YouTube.

Further reading: TP LInk, TP Link SR20 Router, Google
Advertisement

Related Stories

Popular Mobile Brands
  1. Know All About Apple's New Liquid Glass Design Language
  2. WWDC: Prepare for iOS 26, iPadOS 26, and the Dazzling Era of Liquid Glass
  3. Nothing Announces 'Now or Nothing' Sale in India: Check All Offers
  4. Samsung Galaxy S25 Ultra Allegedly Saves Life by Stopping Shrapnel
  5. Android 16 Update Is Coming Soon - Here's What to Expect
  6. iOS 26, iPadOS 26 Are Compatible With These iPhone and iPad Models
  7. NASA Slightly Raises Odds of Asteroid Hitting the Moon in 2032 After Updated JWST Data
  8. Nothing Phone 3 Leaked Render Suggests Design, Triple Rear Camera Unit
  9. Motorola Edge 60 With 5,500mAh Battery Launched in India: Price, Offers
  1. NASA Slightly Raises Odds of Asteroid Hitting the Moon in 2032 After Updated JWST Data
  2. James Webb Space Telescope Captures Stunning Near-Infrared View of Sombrero Galaxy
  3. Perseverance Rover Studies Ancient Martian Rocks at Fallbreen and Forlandet Quadrangle
  4. The Prosecutor OTT Release Date: When and Where to Watch it Online?
  5. Eleven OTT Release Date Announced: Know Where to Watch This Tamil Crime Thriller
  6. Nothing Announces 'Now or Nothing’ Sale in India for Nothing and CMF-Branded Products
  7. What is Liquid Glass Interface, Apple’s New Universal Design Language for iPhone, iPad, Mac, and Other Devices
  8. Activision Says It's Working With Nintendo to Bring Call of Duty to Switch After Black Ops 7 Reveal
  9. Asus TUF Gaming F16, TUF Gaming A16, ROG Strix G16 and ROG Zephyrus G14 2025 Variants Launched in India
  10. UK Bolsters Web3 Investigations, Appoints First Crypto Intelligence Specialist to Insolvency Service
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2025. All rights reserved.