UNIX Symbolic Link (Symlink) Following in TP-Link Archer C9(US)_V1_180125 firmware allows an unauthenticated actor, with physical access and network access, to read sensitive files and write to a limited set of files after plugging a crafted USB drive into the router.
2020-11-21T06:15:12.537
2024-11-21T05:34:36.923
Modified
CVSSv3.1: 6.1 (MEDIUM)
AV:L/AC:L/Au:N/C:P/I:P/A:N
3.9
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tp-link | archer_c9_firmware | 180125 | Yes |
Hardware | tp-link | archer_c9 | v1 | No |