PT-2019-3093 · Tp Link · Tp-Link Archer C2+1
Published
2019-08-27
·
Updated
2019-09-04
·
CVE-2019-13268
CVSS v2.0
8.3
High
| Vector | AV:A/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer C3200 version 1
TP-Link Archer C2 version 1
Description
The issue is related to insufficient compartmentalization between a host network and a guest network established by the same device. These devices forward ARP requests between the host and guest networks, which can be used as a direct covert channel. An attacker can exploit this by sending an ARP request to an arbitrary computer on the network. The data payload can be either the lower 8 bits of the IP address or the entire 32 bits, depending on the router's restriction of ARP forwarding.
Recommendations
For TP-Link Archer C3200 version 1: Consider restricting ARP forwarding to requests destined for the network's subnet mask to minimize the risk of exploitation.
For TP-Link Archer C2 version 1: Consider restricting ARP forwarding to requests destined for the network's subnet mask to minimize the risk of exploitation.
As a temporary workaround, consider disabling the forwarding of ARP requests between the host and guest networks until a patch is available.
Exploit
Fix
RCE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tp-Link Archer C2
Tp-Link Archer C3200