PT-2024-4790 · Tp Link · Tp-Link Tl-7Dr5130
Ke Xu
+4
·
Published
2024-06-10
·
Updated
2024-08-14
·
CVE-2024-37662
CVSS v2.0
6.7
Medium
| Vector | AV:A/AC:L/Au:S/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions:
TP-LINK TL-7DR5130 version 1.0.23
Description:
The issue is related to insufficient validation of the communication channel source, which can be exploited by an attacker to perform a TCP Reset attack. This can be done by sending specially crafted RST messages to a remote server, potentially allowing the attacker to disconnect or hijack the traffic between the victim and the server. An attacker in the same WLAN as the victim can exploit this by sending forged TCP RST messages to evict NAT mappings in the router.
Recommendations:
For TP-LINK TL-7DR5130 version 1.0.23, consider restricting access to port 50005 as a temporary workaround to minimize the risk of exploitation. Additionally, avoid using the router's WLAN functionality until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-7Dr5130