CVE-2020-35575
Last modified
CVE-2020-35575 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.. EPSS estimates a 7.64% chance of exploitation in the next 30 days.
Description
A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Wa901nd Firmware | < 3.16.9\(201211\)_beta |
| Tp-Link | Archer C5 Firmware | All versions |
| Tp-Link | Archer C7 Firmware | All versions |
| Tp-Link | Mr3420 Firmware | All versions |
| Tp-Link | Mr6400 Firmware | All versions |
| Tp-Link | Wa701nd Firmware | All versions |
| Tp-Link | Wa801nd Firmware | All versions |
| Tp-Link | Wdr3500 Firmware | All versions |
| Tp-Link | Wdr3600 Firmware | All versions |
| Tp-Link | We843n Firmware | All versions |
| Tp-Link | Wr1043nd Firmware | All versions |
| Tp-Link | Wr1045nd Firmware | All versions |
| Tp-Link | Wr740n Firmware | All versions |
| Tp-Link | Wr741nd Firmware | All versions |
| Tp-Link | Wr749n Firmware | All versions |
| Tp-Link | Wr802n Firmware | All versions |
| Tp-Link | Wr840n Firmware | All versions |
| Tp-Link | Wr841hp Firmware | All versions |
| Tp-Link | Wr841n Firmware | All versions |
| Tp-Link | Wr842n Firmware | All versions |
| Tp-Link | Wr842nd Firmware | All versions |
| Tp-Link | Wr845n Firmware | All versions |
| Tp-Link | Wr940n Firmware | All versions |
| Tp-Link | Wr941hp Firmware | All versions |
| Tp-Link | Wr945n Firmware | All versions |
| Tp-Link | Wr949n Firmware | All versions |
| Tp-Link | Wrd4300 Firmware | All versions |
References
- http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://pastebin.com/F8AuUdckThird Party Advisory
- https://www.tp-link.com/us/securityVendor Advisory
- http://packetstormsecurity.com/files/163274/TP-Link-TL-WR841N-Command-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://pastebin.com/F8AuUdckThird Party Advisory
- https://www.tp-link.com/us/securityVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-35575?
How severe is CVE-2020-35575?
How do I fix CVE-2020-35575?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-35569An issue was discovered in MB CONNECT LINE mymbCONNECT24 and…6.1
- CVE-2020-3557A vulnerability in the host input API daemon of Cisco Firepo…5.3
- CVE-2020-35570An issue was discovered in MB connect line mymbCONNECT24, mb…5.3
- CVE-2020-35571An issue was discovered in MantisBT through 2.24.3. In the h…6.1
- CVE-2020-35572Adminer through 4.7.8 allows XSS via the history parameter t…6.1
- CVE-2020-35573srs2.c in PostSRSd before 1.10 allows remote attackers to ca…7.5
- CVE-2020-35576A Command Injection issue in the traceroute feature on TP-Li…8.8
- CVE-2020-35577In Endalia Selection Portal before 4.205.0, an Insecure Dire…6.5
- CVE-2020-35578An issue was discovered in the Manage Plugins page in Nagios…7.2
- CVE-2020-35579tindy2013 subconverter 0.6.4 has a /sub?target=%TARGET%&url=…7.5
- CVE-2020-3558A vulnerability in the web-based management interface of Cis…6.1
- CVE-2020-35580A local file inclusion vulnerability in the FileServlet in a…7.5
Are you affected by CVE-2020-35575?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
