7.5

CVE-2022-4499

The strcmp function in TP-Link routers, Archer C5 and WR710N-V1, used for checking credentials in httpd, is susceptible to a side-channel attack.

TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd process, an attacker could guess each byte of the username and password.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Archer C5 Firmware Version 2_160201_us
   Tp-link ≫ Archer C5 Version 2.0
Tp-link ≫ Tl-wr710n Firmware Version 1_151022_us
   Tp-link ≫ Tl-wr710n Version 1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.486
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA-ADP 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CWE-203 Observable Discrepancy

The product behaves differently or sends different responses under different circumstances in a way that is observable to an unauthorized actor.

https://kb.cert.org/vuls/id/572615
Third Party Advisory
VDB Entry
https://www.kb.cert.org/vuls/id/572615