vendor:
Archer C50
by:
Wadeek
8.8
CVSS
HIGH
Cross-Site Request Forgery (Configuration File Disclosure)
352
CWE
Product Name: Archer C50
Affected Version From: <= Build 171227
Affected Version To: <= Build 171227
Patch Exists: YES
Related CWE: N/A
CPE: h:tp-link:archer_c50_v3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: N/A
2018
TP-Link Archer C50 Wireless Router 171227 – Cross-Site Request Forgery (Configuration File Disclosure)
A Cross-Site Request Forgery (CSRF) vulnerability was discovered in TP-Link Archer C50 Wireless Router 171227. An attacker can exploit this vulnerability to disclose the configuration file of the router.
Mitigation:
The vendor has released a firmware update to address this vulnerability. Users are advised to update their devices to the latest version.