PT-2019-3093 · Tp Link · Tp-Link Archer C2+1

Published

2019-08-27

·

Updated

2019-09-04

·

CVE-2019-13268

CVSS v2.0

8.3

High

VectorAV:A/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions TP-Link Archer C3200 version 1 TP-Link Archer C2 version 1
Description The issue is related to insufficient compartmentalization between a host network and a guest network established by the same device. These devices forward ARP requests between the host and guest networks, which can be used as a direct covert channel. An attacker can exploit this by sending an ARP request to an arbitrary computer on the network. The data payload can be either the lower 8 bits of the IP address or the entire 32 bits, depending on the router's restriction of ARP forwarding.
Recommendations For TP-Link Archer C3200 version 1: Consider restricting ARP forwarding to requests destined for the network's subnet mask to minimize the risk of exploitation. For TP-Link Archer C2 version 1: Consider restricting ARP forwarding to requests destined for the network's subnet mask to minimize the risk of exploitation. As a temporary workaround, consider disabling the forwarding of ARP requests between the host and guest networks until a patch is available.

Exploit

Fix

RCE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03076
CVE-2019-13268

Affected Products

Tp-Link Archer C2
Tp-Link Archer C3200