CVE-2024-54127
Exposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
05 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to obtain Wi-Fi credentials of the targeted system.
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
TP-Link · Archer C50 Wireless RouterWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →