CVE-2021-31658
Last modified
CVE-2021-31658 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Tp-Link | Tl-Sg2005 Firmware | 1.0.0 | Build 20180529 Rel.40524 |
| Tp-Link | Tl-Sg2008 Firmware | 1.0.0 | Build 20180529 Rel.40524 |
References
- http://tp-link.comVendor Advisory
- https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658Exploit, Third Party Advisory
- http://tp-link.comVendor Advisory
- https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31658?
How severe is CVE-2021-31658?
How do I fix CVE-2021-31658?
Are you affected by CVE-2021-31658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
