PT-2024-9088 · Tp Link · Tp-Link Archer C7
Published
2024-11-13
·
Updated
2024-12-02
·
CVE-2024-53623
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
TP-Link ARCHER-C7 version v5
Description:
The issue is related to incorrect access control in the
l 0 0.xml component, which allows attackers to access sensitive information. This can be exploited by a remote attacker to gain unauthorized access to protected information. The estimated number of potentially affected devices and details about real-world incidents where this issue was exploited are not provided.Recommendations:
For TP-Link ARCHER-C7 version v5, update the router firmware to the latest version and restrict network access to minimize the risk of exploitation. As a temporary workaround, consider restricting access to the
l 0 0.xml component until a patch is available.Exploit
Fix
Missing Authentication
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tp-Link Archer C7