Today > | 10 High | 17 Medium vulnerabilities   -   You can now download lists of IOCs here!

CVE-2024-54126

Dec. 5, 2024, 1:15 p.m.

Product(s) Impacted

TP-Link Archer C50

Description

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

Weaknesses

CWE-347
Improper Verification of Cryptographic Signature

The product does not verify, or incorrectly verifies, the cryptographic signature for data.

CWE ID: 347

Date

Published: Dec. 5, 2024, 1:15 p.m.

Last Modified: Dec. 5, 2024, 1:15 p.m.

Status : Awaiting Analysis

CVE has been recently published to the CVE List and has been received by the NVD.

More info

Source

vdisclose@cert-in.org.in

References

https://www.cert-in.org.in/ vdisclose@cert-in.org.in