9.8
CVSSv3

CVE-2020-35575

Published: 26/12/2020 Updated: 07/11/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote malicious user to get full administrative access to the web panel. This affects WA901ND devices prior to 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link wa901nd_firmware

tp-link archer_c5_firmware -

tp-link archer_c7_firmware -

tp-link mr3420_firmware -

tp-link mr6400_firmware -

tp-link wa701nd_firmware -

tp-link wa801nd_firmware -

tp-link wdr3500_firmware -

tp-link wdr3600_firmware -

tp-link we843n_firmware -

tp-link wr1043nd_firmware -

tp-link wr1045nd_firmware -

tp-link wr740n_firmware -

tp-link wr741nd_firmware -

tp-link wr749n_firmware -

tp-link wr802n_firmware -

tp-link wr840n_firmware -

tp-link wr841hp_firmware -

tp-link wr841n_firmware -

tp-link wr842n_firmware -

tp-link wr842nd_firmware -

tp-link wr845n_firmware -

tp-link wr940n_firmware -

tp-link wr941hp_firmware -

tp-link wr945n_firmware -

tp-link wr949n_firmware -

tp-link wrd4300_firmware -

Exploits

TP-Link TL-WR841N suffers from a remote command injection vulnerability ...