PT-2021-7051 · Tp Link · Tp-Link Ax10

Published

2021-11-30

·

Updated

2023-08-08

·

CVE-2021-40288

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions TP-Link AX10v1 version V1 211014 and earlier
Description A denial-of-service attack in WPA2 and WPA3-SAE authentication methods allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending wireless adapter specific spoofed authentication frames. The issue is related to errors in security settings of the TP-Link Archer AX10 router's firmware.
Recommendations For TP-Link AX10v1 version V1 211014 and earlier, update to a version later than V1 211014 to resolve the issue. As a temporary workaround, consider restricting access to the wireless network to minimize the risk of exploitation.

Fix

Authentication Bypass by Spoofing

Exposure of Resource to Wrong Sphere

Weakness Enumeration

Related Identifiers

BDU:2022-03101
CVE-2021-40288

Affected Products

Tp-Link Ax10