Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-27246


This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP message can write stack pointers to the stack. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-12306.


Published

2021-04-14T16:15:13.127

Last Modified

2024-11-21T05:57:40.697

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.0 (HIGH)

CVSSv2 Vector

AV:A/AC:M/Au:N/C:C/I:C/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: MEDIUM
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

5.5

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-121

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link ac1750_firmware 1.0.15 Yes
Hardware tp-link ac1750 a7 No

References