Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxqc-mrq8-7966

Опубликовано: 08 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 6.8
CVSS3: 5.7

Описание

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

EPSS

Процентиль: 21%
0.00286
Низкий

6.8 Medium

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-15
CWE-610

Связанные уязвимости

CVSS3: 5.7
nvd
4 месяца назад

An external control of configuration vulnerability in the OpenVPN module of TP-Link AX53 v1.0 allows an authenticated adjacent attacker to read arbitrary file when a malicious configuration file is processed.  Successful exploitation may allow unauthorized access to arbitrary files on the device, potentially exposing sensitive information.This issue affects AX53 v1.0: before 1.7.1 Build 20260213.

EPSS

Процентиль: 21%
0.00286
Низкий

6.8 Medium

CVSS4

5.7 Medium

CVSS3

Дефекты

CWE-15
CWE-610