Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h688-4pc2-376f

Опубликовано: 03 мая 2024
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the hotplugd daemon. The issue results from firewall rule handling that allows an attacker access to resources that should be available to the LAN interface only. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the root user. Was ZDI-CAN-19664.

TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the hotplugd daemon. The issue results from firewall rule handling that allows an attacker access to resources that should be available to the LAN interface only. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the root user. Was ZDI-CAN-19664.

EPSS

Процентиль: 83%
0.01874
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 8.1
nvd
почти 2 года назад

TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hotplugd daemon. The issue results from firewall rule handling that allows an attacker access to resources that should be available to the LAN interface only. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the root user. . Was ZDI-CAN-19664.

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения маршрутизатор TP-Link Archer AX21 (AX1800), связанная с ошибками синхронизации при использовании общего ресурса («Ситуация гонки»), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 83%
0.01874
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-362