Логотип exploitDog
bind:CVE-2022-43636
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43636

Количество 3

Количество 3

nvd логотип

CVE-2022-43636

почти 3 года назад

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of sufficient randomness in the sequnce numbers used for session managment. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-18334.

CVSS3: 8.8
EPSS: Низкий
github логотип

GHSA-3fvg-68xh-vfxq

почти 3 года назад

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of sufficient randomness in the sequnce numbers used for session managment. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-18334.

CVSS3: 8.8
EPSS: Низкий
fstec логотип

BDU:2022-07130

около 3 лет назад

Уязвимость httpd-демона микропрограммного обеспечения маршрутизаторов TP-Link TL-WR940N, позволяющая нарушителю обойти процесс аутентификации и получить несанкционированный доступ к оборудованию

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-43636

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of sufficient randomness in the sequnce numbers used for session managment. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-18334.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
github логотип
GHSA-3fvg-68xh-vfxq

This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of TP-Link TL-WR940N 6_211111 3.20.1(US) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from the lack of sufficient randomness in the sequnce numbers used for session managment. An attacker can leverage this vulnerability to bypass authentication on the system. Was ZDI-CAN-18334.

CVSS3: 8.8
0%
Низкий
почти 3 года назад
fstec логотип
BDU:2022-07130

Уязвимость httpd-демона микропрограммного обеспечения маршрутизаторов TP-Link TL-WR940N, позволяющая нарушителю обойти процесс аутентификации и получить несанкционированный доступ к оборудованию

CVSS3: 7.5
0%
Низкий
около 3 лет назад

Уязвимостей на страницу