CVE-2021-3275 Information

Description

Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers) Access Points ADSL + DSL Gateways and Routers which affects TD-W9977v1 TL-WA801NDv5 TL-WA801Nv6 TL-WA802Nv5 and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm networkMap.htm dhcpClient.htm qsEdit.htm and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Reference

https://www.tp-link.com https://seclists.org/fulldisclosure/2021/Mar/67 https://github.com/smriti548/CVE/blob/main/CVE-2021-3275 http://packetstormsecurity.com/files/161989/TP-Link-Cross-Site-Scripting.html

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

REQUIRED

Confidentiality Impact

CHANGED

Integrity Impact

LOW

Availability Impact

LOW

Base Score

NONE

Base Severity

6.1

Share on: