CVE-2020-35575
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (7.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 7.64% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- tp-link/wa901nd firmware · tp-link/archer c5 firmware · tp-link/archer c7 firmware · tp-link/mr3420 firmware · tp-link/mr6400 firmware · tp-link/wa701nd firmware · tp-link/wa801nd firmware · tp-link/wdr3500 firmware · tp-link/wdr3600 firmware · tp-link/we843n firmware · tp-link/wr1043nd firmware · tp-link/wr1045nd firmware · tp-link/wr740n firmware · tp-link/wr741nd firmware · tp-link/wr749n firmware · tp-link/wr802n firmware · tp-link/wr840n firmware · tp-link/wr841hp firmware · tp-link/wr841n firmware · tp-link/wr842n firmware · +7 more
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://pastebin.com/F8AuUdckThird Party Advisory
- https://static.tp-link.com/2020/202012/20201214/wa901ndv5_eu_3_16_9_up_boot%28201211%29.zip
- https://www.tp-link.com/us/securityVendor Advisory
- http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://pastebin.com/F8AuUdckThird Party Advisory
- https://static.tp-link.com/2020/202012/20201214/wa901ndv5_eu_3_16_9_up_boot%28201211%29.zip
- https://www.tp-link.com/us/securityVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.