Description
Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.
No analysis available yet.
Remediation
Vendor Solution
Update the firmware to Archer AX50(EU)_V1_1.0.14 build 20240108.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-27150 | Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded. |
References
History
No history.
Status: PUBLISHED
Assigner: INCIBE
Published:
Updated: 2024-08-02T19:36:42.551Z
Reserved: 2024-03-05T09:35:08.297Z
Link: CVE-2024-2188
Updated: 2024-08-01T19:03:39.107Z
Status : Awaiting Analysis
Published: 2024-03-05T13:15:07.203
Modified: 2024-11-21T09:09:13.210
Link: CVE-2024-2188
No data.
OpenCVE Enrichment
Updated: 2025-07-12T22:31:46Z
Weaknesses
EUVD