Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-222x-w66m-px4x

Опубликовано: 05 дек. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.5

Описание

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

EPSS

Процентиль: 1%
0.00008
Низкий

8.5 High

CVSS4

Дефекты

CWE-347

Связанные уязвимости

nvd
7 месяцев назад

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

CVSS3: 6.8
fstec
7 месяцев назад

Уязвимость веб-интерфейса управления микропрограммного обеспечения Wi‑Fi роутеров TP-Link Archer C50, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00008
Низкий

8.5 High

CVSS4

Дефекты

CWE-347