Remote Authentication Bypass in TP-Link Archer C5v Devices
CVE-2021-27210
6.5MEDIUM
Summary
The TP-Link Archer C5v 1.7_181221 devices are susceptible to an improper authorization vulnerability, allowing remote attackers to access sensitive information. By exploiting this flaw, attackers can retrieve cleartext user credentials through a specifically crafted URI, enabling potential unauthorized access and compromise of the device's settings. This highlights the importance of securing these devices against unauthorized access to protect user data.
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved