| CVE |
Vendors |
Products |
Updated |
CVSS v3.1 |
| A hard-coded
cryptographic key vulnerability exists in the web module of TP-Link Archer
AX55 v4. A LAN attacker who captures an HTTP login session may use the known
shared RSA private key to decrypt the administrator password; the
weakened AES session key further reduces the effort required to
compromise session confidentiality.
Successful
exploitation may disclose the administrator password captured from an HTTP
login session and compromise session confidentiality. |
| A
stack-based buffer overflow vulnerability exists in the EasyMesh module of
TP-Link Archer AX55 v4. When Mesh mode is enabled, a LAN attacker may submit
crafted input that causes the easymesh daemon to crash and may potentially
achieve remote code execution on the device.
Successful
exploitation may cause the EasyMesh daemon to crash and may potentially allow
remote code execution when Mesh mode is enabled. This
may result in high impact to the confidentiality, integrity, and availability
of the affected device. |
| TP-Link TL-WR841N dropbearpwd Improper Authentication Information Disclosure Vulnerability. This vulnerability allows network-adjacent attackers to disclose sensitive information on affected installations of TP-Link TL-WR841N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the httpd service, which listens on TCP port 80 by default. The issue results from improper authentication. An attacker can leverage this vulnerability to disclose stored credentials, leading to further compromise. Was ZDI-CAN-19899. |
| A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as an OpenVPN Server due to insufficient validation of client-supplied data during OpenVPN connection establishment. An unauthenticated remote attacker may provide specially crafted input influencing backend command execution logic before authentication completes. Exploitation requires the OpenVPN Server feature to be enabled, VPN service reachable by the attacker and attacker to be able to initiate an OpenVPN connection attempt.
Successful exploitation may allow arbitrary command execution, potentially
leading to full compromise of the affected device. |
| An
unauthenticated denial-of-service vulnerability was identified in TP-Link TL-MR100 v3.2, TL-MR150 v3.2, TL-MR6400 v8.0 and Archer MR600 v2, due to improper handling of exceptional request conditions
that may lead to a NULL pointer dereference.
A remote attacker on an adjacent network can send a specially crated
HTTP request to trigger a crash of the HTTP service process.
Successful
exploitation may cause the HTTP service to crash, making the web management
interface and HTTP-dependent functionality temporarily unavailable. |
| A pre-authentication stack-based buffer overflow vulnerability exists in the http_gdpr_decrypt function of TL-MR100 V3.20 due to insufficient bounds checking of encrypted requests to the /cgi/login endpoint. An adjacent unauthenticated attacker with access to the router's web management interface can trigger memory corruption and potentially achieve arbitrary code execution.
Successful exploitation can overwrite saved control-flow data on the httpd process stack prior to authentication, resulting in a service crash or potential arbitrary code execution in the context of the affected process. |
| A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing SOAP action requests. A specially crafted SOAP action request containing unexpected XML content may cause the UPnP daemon to terminate unexpectedly.
Successful exploitation may result in a denial-of-service condition affecting UPnP functionality until the service is restarted or the device is rebooted. |
| A NULL
pointer dereference vulnerability exists in TL-WR841N v14 in the UPnP service when processing
SOAP state variable query requests. A specially crafted SOAP query may trigger
unexpected termination or instability of the process hosting the UPnP service.
Successful
exploitation may result in a denial-of-service condition affecting UPnP
discovery, state query, or related management functionality until the affected
process is restarted or the device is rebooted. |
| A buffer
overflow vulnerability exists in the embedded HTTP service in TL-WR841N v14 when processing
multipart/form-data requests. Insufficient validation of an attacker-controlled
boundary parameter may allow a remote unauthenticated attacker to submit a
crafted request that corrupts memory by overwriting data beyond the bounds of
an internal buffer.
Successful
exploitation may result in modification or corruption of process memory,
potentially leading to undefined application behavior. Arbitrary code
execution, information disclosure, and denial-of-service conditions have not
been demonstrated. |
| Tapo C120 v1 and C200 v5
contain an improper authentication vulnerability within the login
authentication verification module. An attacker on the local network can
exploit weaknesses in challenge parameter validation to bypass normal
authentication controls and obtain administrative session tokens.
Successful
exploitation may allow an attacker to subsequently execute privileged
management actions, enable unauthorized administrative access and temporary
disruption of device services, resulting in a denial-of-service (DoS)
condition. |
| A Zip Slip vulnerability in the WebUI ISP
Upgrade functionality allows arbitrary file write via a crafted archive
containing directory traversal sequences. An authenticated administrator may
overwrite arbitrary files on the system.Successful
exploitation may allow arbitrary file to be overwritten on the underlying system, affecting system integrity and availability. |
| The use of
hard-coded cryptographic key vulnerability has been identified in the mesh
functionality of Deco XE75 v3, XE5300 v3.6 and WE10800 v3.6.
A shared RSA-512 mesh group private key is present in the affected
firmware and is used by the mesh protocol for node authentication. An attacker who obtains the firmware image
and has local network access may be able to authenticate as a mesh node without
possessing a device-specific credential.
Successful
exploitation may allow an unauthenticated adjacent attacker to impersonate a
trusted mesh node and bypass mesh node authentication, which may permit unauthorized
changes to device or mesh configuration, affecting confidentiality, integrity
and availability. |
| An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, BE3600 V1, and AX75 V1 due to improper filtering and neutralization of special characters in certain parameters. A LAN-based attacker can inject arbitrary commands and execute them with root privileges.
Successful exploitation may result in complete device compromise and impact the confidentiality, integrity, and availability of the affected device and network traffic. |
| An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative access to execute arbitrary system commands with root privileges by injecting shell metacharacters via a VPN connection.
Successful exploitation may enable persistent backdoors, credential theft, LAN reconnaissance, and router-assisted attacks against connected devices. |
| A stored OS
command injection vulnerability exists in the parent-control module of TP-Link
Archer BE3600 V1. An authenticated adjacent attacker with administrative access
may store a crafted profile name containing shell metacharacters, which is
later processed unsafely during daily cloud report generation and may result in
arbitrary command execution.
Successful
exploitation may allow command execution on the affected device with potential
impact to device confidentiality, integrity, and availability. |
| An OS command injection vulnerability exists in the web management interface of Archer C20 v6 firmware when processing certain WAN-related configuration operations. An authenticated administrator may exploit insufficient input validation to execute arbitrary system commands, potentially resulting in full device compromise.
Successful exploitation may allow arbitrary command execution with elevated privileges, compromising the confidentiality, integrity, and availability of the affected device and network traffic passing through it. |
| A
stack-based buffer overflow vulnerability exists in the firmware update
functionality of TL-MR6400 v7 due to unsafe processing of
attacker-controlled metadata within a firmware image.
Successful
exploitation may allow an authenticated attacker to trigger memory corruption
and execute arbitrary code on the affected device. |
| An improper input
validation vulnerability in the configuration service for processing encrypted
credential data has been identified in Tapo C200 v5. An attacker can send oversized crypted
ciphertext values that may trigger exception handling failures, due to insufficient
validation, causing the affected device to crash or restart.
Successful
exploitation may temporarily disrupt HTTPS management and monitoring
functionality, resulting in a denial-of-service (DoS) condition until the
service recovers. |
| A NULL
pointer dereference vulnerability exists in the HTTP request parsing
functionality of
TL-MR6400 v7. An unauthenticated remote attacker can
trigger the vulnerability by sending a specially crafted HTTP request
containing a malformed session cookie header.
Successful
exploitation may cause the HTTP service process to crash, resulting in a
denial-of-service condition and temporary loss of management or CGI
functionality until service recovery. |
| A
stack-based out-of-bounds write vulnerability exists in the login request
handling functionality of the administrative web interface of TP-Link TL-MR6400 v7 routers. An unauthenticated adjacent attacker can trigger the vulnerability
by sending a specially crafted malformed HTTP request.
Successful
exploitation may cause the web service process to crash, resulting in a
denial-of-service condition and temporary loss of access to the router's web
management interface. |