CVE-2024-54127
Exposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50
Vexday Risk Score
13Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 4.3EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
05 dic 2024Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to obtain Wi-Fi credentials of the targeted system.
CVSS:4.0/AV:P/AC:H/AT:N/PR:N/UI:N/VC:H/VI:N/VA:L/SC:N/SI:N/SA:N
Productos afectados
TP-Link · Archer C50 Wireless Router¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →