CVE-2020-24363
HIGH(8.8)KEVErhöhtes Risiko
TP-link TL-WA855RE Missing Authentication for Critical Function Vulnerability
Beschreibung
TP-Link TL-WA855RE V5 20200415-rel37464 devices allow an unauthenticated attacker (on the same network) to submit a TDDP_RESET POST request for a factory reset and reboot. The attacker can then obtain incorrect access control by setting a new administrative password.
KEV-Informationen
CVSS-Score
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HIm Rechner öffnenBetroffene Produkte
| Hersteller | Produkt | Version |
|---|---|---|
| tp-link | tl-wa855re firmware | < 200731 |
Mehrere CVSS-Bewertungen
Quelle: [email protected](Primary)
8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Quelle: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Referenzen
- http://malwrforensics.com/en/2020/08/31/cve-2020-24363-tl-wa855re-v5-advisory/(Third Party Advisory)
- https://pastebin.com/VjHM4UiA(Third Party Advisory)
- https://www.tp-link.com/us/support/download/tl-wa855re/#Firmware(Product)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-24363(US Government Resource)
Hilfe beim Schwachstellenmanagement?
Unsere Sicherheitsexperten helfen Ihnen bei der Priorisierung und Behebung von Schwachstellen.