Описание
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
EPSS
Процентиль: 16%
0.00247
Низкий
Дефекты
CWE-693
Связанные уязвимости
github
7 месяцев назад
When configured as L2TP/IPSec VPN server, Archer AXE75 V1 may accept connections using L2TP without IPSec protection, even when IPSec is enabled. This allows VPN sessions without encryption, exposing data in transit and compromising confidentiality.
CVSS3: 7.5
fstec
7 месяцев назад
Уязвимость реализации протокола L2TP/IPSec VPN server микропрограммного обеспечения Wi‑Fi роутера TP-Link Archer AXE75, позволяющая нарушителю раскрыть защищаемую информацию
EPSS
Процентиль: 16%
0.00247
Низкий
Дефекты
CWE-693