Project Subscriptions
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 12 Feb 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. | A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. NOTE: this is disputed by the Supplier because the response to the API call is only "non-sensitive UI initialization variables." |
Fri, 06 Jun 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Tp-link
Tp-link archer C20 Tp-link archer C20 Firmware |
|
| CPEs | cpe:2.3:h:tp-link:archer_c20:6.6:*:*:*:*:*:*:* cpe:2.3:o:tp-link:archer_c20_firmware:6.6_230412:*:*:*:*:*:*:* |
|
| Vendors & Products |
Tp-link
Tp-link archer C20 Tp-link archer C20 Firmware |
Wed, 19 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-287 | |
| Metrics |
cvssV3_1
|
Tue, 18 Feb 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the TP-Link Archer c20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass the authentication of some interfaces under the /cgi directory. When adding Referer: http://tplinkwifi.net to the the request, it will be recognized as passing the authentication. | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-02-12T05:03:22.325Z
Reserved: 2025-01-09T00:00:00.000Z
Link: CVE-2024-57049
Updated: 2025-02-19T14:49:49.326Z
Status : Modified
Published: 2025-02-18T15:15:16.890
Modified: 2026-02-12T06:16:00.430
Link: CVE-2024-57049
No data.
OpenCVE Enrichment
No data.