TP-Link SR20 Router Vulnerability Disclosed by Google Researcher After No Response From Company

Advertisement
By Tasneem Akolawala | Updated: 29 March 2019 14:16 IST
Highlights
  • Google researcher told TP-Link of this issue in December
  • He got no response from the company, his tweet was also ignored
  • He then published the TP-Link SR20 router vulnerability online

TP-Link vulnerability exposes type 1 commands for attackers to exploit

According to Google security researcher Matthew Garrett, TP-Link's SR20 Smart Home Router comes with a vulnerability that allows arbitrary command execution from a local network connection. This exploit was disclosed by the researcher after he was unable to solicit a response from TP-Link, and even published a proof-of-concept to demonstrate the vulnerability. The router, which was launched in 2016, exposes a number of commands that come with root privileges and does not even require authentication. Garrett disclosed the proof-of-concept, after waiting for the Google Project Zero team's 90-day deadline for disclosure to elapse.

Garrett took to Twitter to explain that the TP Link SR20 Smart Home Router comes with TDDP (TP-Link Device Debug Protocol), which is affected with several vulnerabilities, and one of them is that version 1 commands are exposed for attackers to exploit.

Advertisement

He says that these exposed commands allow attackers to send a command containing a filename, a semicolon, to execute the process. “This connects back to the machine that sent the command and attempts to download a file via TFTP (Trivial File Transfer Protocol) corresponding to the filename it sent. The main TDDP process waits up to four seconds for the file to appear - once it does, it loads the file into a Lua interpreter it initialised earlier, and calls the function config_test() with the name of the config file and the remote address as arguments. Since config_test() is provided by the file that was downloaded from the remote machine, this gives arbitrary code execution in the interpreter, which includes the os.execute method which just runs commands on the host. Since TDDP is running as root, you get arbitrary command execution as root,” he explains on the blog.

This process allows for full takeover of the SR20 router. Garett says he reported to TP-Link of this vulnerability in December, via its security disclosure form. The page told him that he would get a response within three days, but hasn't heard back from them till date. He also said that he tweeted at TP-Link regarding the matter, but that garnered no response either.

Advertisement

He ends by suggesting to the company, “Don't default to running debug daemons on production firmware”, and, “If you're going to have a security disclosure form, read it.”

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Further reading: TP LInk, TP Link SR20 Router, Google
Advertisement

Related Stories

Popular Mobile Brands
  1. New iPhone 18 Pro Leak Suggests It Could Arrive in These Battery Variants
  2. Amazon Will Soon Make You Pay More for Ad-Free Music Streaming in India
  3. Itel Aqua Launched in India With IP67 Rating, 1,200mAh Battery: See Price
  4. Moto G37 Power Review: Covers All the Bases and More
  5. Find X9 Ultra Review: Oppo's Crown Jewel
  6. Apple Brings New Wallpaper, Apple Music Playlist Ahead of WWDC 2026
  7. Asus Pad With MediaTek Dimensity 8300 Chip, 9,000mAh Battery Unveiled
  8. Asus Unveils Zenbook 14 at Computex 2026, New Vivobook S Series Tags Along
  9. Xiaomi's Phones Now Let You Share Files With iPhone Models via AirDrop
  1. Asus Zenbook 14, Vivobook S14, Vivobook S16, Vivobook S14 Flip and Vivobook S16 Flip Launched at Computex 2026
  2. Asus Pad With MediaTek Dimensity 8300 Chip, 9,000mAh Battery Unveiled at Computex 2026
  3. Amazon Music to Play ‘Limited Ads’ for Prime Members in India as Firm Offers Unlimited Plan With Ad-Free Music Streaming
  4. Apple Rolls Out iOS 26.5.1 Update With Fix for Charging Bug Affecting iPhone Air, iPhone 17 Models
  5. Asus ROG Xbox Ally X20 With Larger 7.4-Inch OLED Display Unveiled at Computex 2026
  6. ViewSonic IN05 Series ViewBoard 4K Displays Launched in India With Android 16, AI Features
  7. Asus ProArt P16, ProArt P14 and New ProArt Mini PC With Nvidia RTX Spark Unveiled at Computex 2026
  8. Computex 2026: MSI Prestige N16 Flip AI+ Announced as Company's First Nvidia RTX Spark-Powered Laptop
  9. Apple Releases New ‘Glow All Out’ Wallpaper, Apple Music Playlist Hinting at Next Week’s WWDC 2026 Theme
  10. Xiaomi's HyperOS 3 Adds AirDrop Support on Select Models With Ability to Share Files With Apple Devices
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.