PT-2022-25402 · Tp Link · Tp Link Archer Ax10

Published

2022-09-28

·

Updated

2022-09-30

·

CVE-2022-40486

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553)
Description The issue allows authenticated attackers to execute arbitrary code via a crafted backup file.
Recommendations For TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553), consider restricting access to the backup file feature until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2022-40486

Affected Products

Tp Link Archer Ax10