Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-27359

Опубликовано: 03 мая 2024
Источник: nvd
CVSS3: 9.8
CVSS3: 8.1
EPSS Низкий

Описание

TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.

The specific flaw exists within the hotplugd daemon. The issue results from firewall rule handling that allows an attacker access to resources that should be available to the LAN interface only. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the root user. . Was ZDI-CAN-19664.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:tp-link:archer_ax21_firmware:1.1.1:build20220603:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_ax21:3.0:*:*:*:*:*:*:*

EPSS

Процентиль: 83%
0.01874
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-362

Связанные уязвимости

CVSS3: 9.8
github
почти 2 года назад

TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability. This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the hotplugd daemon. The issue results from firewall rule handling that allows an attacker access to resources that should be available to the LAN interface only. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the root user. Was ZDI-CAN-19664.

CVSS3: 9.8
fstec
почти 3 года назад

Уязвимость микропрограммного обеспечения маршрутизатор TP-Link Archer AX21 (AX1800), связанная с ошибками синхронизации при использовании общего ресурса («Ситуация гонки»), позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 83%
0.01874
Низкий

9.8 Critical

CVSS3

8.1 High

CVSS3

Дефекты

CWE-362