← back
CVE-2024-54127

Exposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50

CVSS 4.3 MEDIUMEPSS 0.1%CWE-312
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 4.3EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
05 Dec 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to obtain Wi-Fi credentials of the targeted system.
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →