A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel
Published Dec 26, 2020
9.8
CRITICALCVSS 3.1
EPSS 7.64%
Description
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.
Affected products
No data.
Configuration 1
- < 3.16.9\(201211\)_beta
Configuration 2
- n/a
Configuration 3
- n/a
Configuration 4
- n/a
Configuration 5
- n/a
Configuration 6
- n/a
Configuration 7
- n/a
Configuration 8
- n/a
Configuration 9
- n/a
Configuration 10
- n/a
Configuration 11
- n/a
Configuration 12
- n/a
Configuration 13
- n/a
Configuration 14
- n/a
Configuration 15
- n/a
Configuration 16
- n/a
Configuration 17
- n/a
Configuration 18
- n/a
Configuration 19
- n/a
Configuration 20
- n/a
Configuration 21
- n/a
Configuration 22
- n/a
Configuration 23
- n/a
Configuration 24
- n/a
Configuration 25
- n/a
Configuration 26
- n/a
Configuration 27
- n/a
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
No CWE recorded.
References (5)
- http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.html x_refsource_MISCExploitThird Party AdvisoryVDB Entry
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23241 Advisory
- https://pastebin.com/F8AuUdck x_refsource_MISCThird Party Advisory
- https://static.tp-link.com/2020/202012/20201214/wa901ndv5_eu_3_16_9_up_boot%28201211%29.zip x_refsource_MISC
- https://www.tp-link.com/us/security x_refsource_MISCVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.html | x_refsource_MISCExploitThird Party AdvisoryVDB Entry | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-23241 | Advisory | |
| https://pastebin.com/F8AuUdck | x_refsource_MISCThird Party Advisory | |
| https://static.tp-link.com/2020/202012/20201214/wa901ndv5_eu_3_16_9_up_boot%28201211%29.zip | x_refsource_MISC | |
| https://www.tp-link.com/us/security | x_refsource_MISCVendor Advisory |
Change history (0)
No recorded changes yet.