9.8

CVE-2020-35575

Exploit

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Data is provided by the National Vulnerability Database (NVD)
Tp-linkWa901nd Firmware Version < 3.16.9\(201211\)_beta
   Tp-linkWa901nd Version-
Tp-linkArcher C5 Firmware Version-
   Tp-linkArcher C5 Version-
Tp-linkArcher C7 Firmware Version-
   Tp-linkArcher C7 Version-
Tp-linkMr3420 Firmware Version-
   Tp-linkMr3420 Version-
Tp-linkMr6400 Firmware Version-
   Tp-linkMr6400 Version-
Tp-linkWa701nd Firmware Version-
   Tp-linkWa701nd Version-
Tp-linkWa801nd Firmware Version-
   Tp-linkWa801nd Version-
Tp-linkWdr3500 Firmware Version-
   Tp-linkWdr3500 Version-
Tp-linkWdr3600 Firmware Version-
   Tp-linkWdr3600 Version-
Tp-linkWe843n Firmware Version-
   Tp-linkWe843n Version-
Tp-linkWr1043nd Firmware Version-
   Tp-linkWr1043nd Version-
Tp-linkWr1045nd Firmware Version-
   Tp-linkWr1045nd Version-
Tp-linkWr740n Firmware Version-
   Tp-linkWr740n Version-
Tp-linkWr741nd Firmware Version-
   Tp-linkWr741nd Version-
Tp-linkWr749n Firmware Version-
   Tp-linkWr749n Version-
Tp-linkWr802n Firmware Version-
   Tp-linkWr802n Version-
Tp-linkWr840n Firmware Version-
   Tp-linkWr840n Version-
Tp-linkWr841hp Firmware Version-
   Tp-linkWr841hp Version-
Tp-linkWr841n Firmware Version-
   Tp-linkWr841n Version-
Tp-linkWr842n Firmware Version-
   Tp-linkWr842n Version-
Tp-linkWr842nd Firmware Version-
   Tp-linkWr842nd Version-
Tp-linkWr845n Firmware Version-
   Tp-linkWr845n Version-
Tp-linkWr940n Firmware Version-
   Tp-linkWr940n Version-
Tp-linkWr941hp Firmware Version-
   Tp-linkWr941hp Version-
Tp-linkWr945n Firmware Version-
   Tp-linkWr945n Version-
Tp-linkWr949n Firmware Version-
   Tp-linkWr949n Version-
Tp-linkWrd4300 Firmware Version-
   Tp-linkWrd4300 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 35.57% 0.967
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P