Insufficient Compartmentalization in TP-Link Router Products
CVE-2019-13268
8.8HIGH
What is CVE-2019-13268?
TP-Link Archer C3200 V1 and Archer C2 V1 devices exhibit insufficient compartmentalization between the host and guest networks. This vulnerability allows ARP requests to be forwarded between both networks without restrictions. As a result, an attacker can exploit this flaw to send ARP requests to arbitrary devices, potentially enabling unauthorized information access or network interference. The routing of these requests without limitations undermines network security measures, putting devices connected to both networks at risk.