ZeroHour

CVE-2020-35575

PoC
CVSS 3.1
9.8 critical
EPSS
8%p94
Published
()
Modified
Description

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Vendors
tp-link
Products
wa901nd firmware, archer c5 firmware, archer c7 firmware, mr3420 firmware, mr6400 firmware, wa701nd firmware, wa801nd firmware, wdr3500 firmware, wdr3600 firmware, we843n firmware, wr1043nd firmware, wr1045nd firmware
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.