Remote Authentication Bypass in TP-Link Archer C5v Devices
CVE-2021-27210

6.5MEDIUM

Key Information:

Vendor
Tp-link
Vendor
CVE Published:
13 February 2021

Summary

The TP-Link Archer C5v 1.7_181221 devices are susceptible to an improper authorization vulnerability, allowing remote attackers to access sensitive information. By exploiting this flaw, attackers can retrieve cleartext user credentials through a specifically crafted URI, enabling potential unauthorized access and compromise of the device's settings. This highlights the importance of securing these devices against unauthorized access to protect user data.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.