vendor:
Archer C50 v3
by:
Wadeek
4.3
CVSS
MEDIUM
Cross-Site Request Forgery (Information Disclosure)
352
CWE
Product Name: Archer C50 v3
Affected Version From: <= Build 171227
Affected Version To: N/A
Patch Exists: YES
Related CWE: N/A
CPE: h:tp-link:archer_c50_v3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
TP-Link C50 Wireless Router 3 – Cross-Site Request Forgery (Information Disclosure)
A Cross-Site Request Forgery (CSRF) vulnerability exists in TP-Link C50 Wireless Router 3, which allows an attacker to disclose sensitive information. The vulnerability exists due to insufficient validation of user-supplied input in the web-based management interface. An attacker can send a specially crafted request to the web-based management interface and disclose sensitive information.
Mitigation:
The vendor has released a patch to address this vulnerability. It is recommended to update the router to the latest version.