CVE-2021-31658
Last modified
CVE-2021-31658 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. EPSS estimates a 1.06% chance of exploitation in the next 30 days.
Description
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Tp-Link | Tl-Sg2005 Firmware | 1.0.0 | Build 20180529 Rel.40524 |
| Tp-Link | Tl-Sg2008 Firmware | 1.0.0 | Build 20180529 Rel.40524 |
References
- https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658Exploit, Third Party Advisory
- https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-31658?
How severe is CVE-2021-31658?
How do I fix CVE-2021-31658?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-31646Gestsup before 3.2.10 allows account takeover through the pa…9.8
- CVE-2021-31649In applications using jfinal 4.9.08 and below, there is a de…9.8
- CVE-2021-3165SmartAgent 3.1.0 allows a ViewOnly attacker to create a Supe…8.8
- CVE-2021-31650A SQL injection vulnerability in Sourcecodester Online Gradi…9.8
- CVE-2021-31651Cross Site Scripting (XSS) vulnerability in neofarg-cms 0.2.…4.8
- CVE-2021-31655Cross Site Scripting (XSS) vulnerability in TRENDnet TV-IP11…6.1
- CVE-2021-31659TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.…8.8
- CVE-2021-3166An issue was discovered on ASUS DSL-N14U-B1 1.1.2.3_805 devi…7.5
- CVE-2021-31660RIOT-OS 2021.01 before commit 85da504d2dc30188b89f44c3276fc5…7.5
- CVE-2021-31661RIOT-OS 2021.01 before commit 609c9ada34da5546cffb632a98b7ba…7.5
- CVE-2021-31662RIOT-OS 2021.01 before commit 07f1254d8537497552e7dce80364aa…7.5
- CVE-2021-31663RIOT-OS 2021.01 before commit bc59d60be60dfc0a05def57d749853…7.5
Are you affected by CVE-2021-31658?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
