vendor:
TP-Link C50 Wireless Router 3
by:
Wadeek
7.5
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: TP-Link C50 Wireless Router 3
Affected Version From:
Affected Version To: Build 171227
Patch Exists: YES
Related CWE:
CPE: h:tp-link:archer_c50_v3:00000001
Platforms Tested:
2018
TP-Link C50 Wireless Router 3 – Cross-Site Request Forgery (Remote Reboot)
This exploit allows an attacker to remotely reboot the TP-Link C50 Wireless Router 3 by sending a forged request. The vulnerability exists in the firmware version <= Build 171227 of the router. By exploiting this vulnerability, an attacker can disrupt the normal functioning of the router.
Mitigation:
To mitigate this vulnerability, TP-Link recommends updating the firmware to the latest version available. Users can download the firmware from the vendor's website (https://www.tp-link.com/download/Archer-C50_V3.html#Firmware).