CVE-2021-3275 Information
Description
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers) Access Points ADSL + DSL Gateways and Routers which affects TD-W9977v1 TL-WA801NDv5 TL-WA801Nv6 TL-WA802Nv5 and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm networkMap.htm dhcpClient.htm qsEdit.htm and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Reference
https://www.tp-link.com https://seclists.org/fulldisclosure/2021/Mar/67 https://github.com/smriti548/CVE/blob/main/CVE-2021-3275 http://packetstormsecurity.com/files/161989/TP-Link-Cross-Site-Scripting.html
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
REQUIRED
Confidentiality Impact
CHANGED
Integrity Impact
LOW
Availability Impact
LOW
Base Score
NONE
Base Severity
6.1
Share on: