Insufficient Compartmentalization in TP-Link Router Products
CVE-2019-13268

8.8HIGH

Key Information:

Vendor
Tp-link
Vendor
CVE Published:
27 August 2019

Summary

TP-Link Archer C3200 V1 and Archer C2 V1 devices exhibit insufficient compartmentalization between the host and guest networks. This vulnerability allows ARP requests to be forwarded between both networks without restrictions. As a result, an attacker can exploit this flaw to send ARP requests to arbitrary devices, potentially enabling unauthorized information access or network interference. The routing of these requests without limitations undermines network security measures, putting devices connected to both networks at risk.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.