PT-2025-6736 · Tp Link · Tp-Link Archer C20

Shuanunio

·

Published

2025-02-18

·

Updated

2026-02-12

·

CVE-2024-57049

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Archer c20 router versions prior to V6.6 230412
Description A flaw exists in the TP-Link Archer c20 router that allows unauthorized access by bypassing authentication for certain interfaces located under the /cgi directory. This bypass is achieved by adding the Referer: http://tplinkwifi.net header to requests. The supplier disputes the severity of this issue, stating that the API call response only contains "non-sensitive UI initialization variables."
Recommendations Update the firmware to version V6.6 230412 or later.

Exploit

Fix

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2025-02160
CVE-2024-57049

Affected Products

Tp-Link Archer C20