Showing 3 vulnerabilities on this page for Archer C5

Signals CISA KEV Ransomware Nuclei
TP-Link vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Archer C5 firmware all versions and Archer C7 firmware versions prior to 'Archer C7(JP)_V2_230602' allow a network-adjacent authenticated attacker to execute arbitrary OS commands. Note that Archer C5 is no longer supported, therefore the update for this product is not provided.

CWE-78Sep 6, 2023
CVSS8.0v3.1EPSS0.35%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

A vulnerable HTTP Basic Authentication process in TP-Link routers, Archer C5 and WR710N-V1, is susceptible to either a DoS or an arbitrary code execution via any interface.

In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution.

CWE-120CWE-787Jan 11, 2023
CVSS9.8v3.1EPSS1.78%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

The strcmp function in TP-Link routers, Archer C5 and WR710N-V1, used for checking credentials in httpd, is susceptible to a side-channel attack.

TP-Link routers, Archer C5 and WR710N-V1, using the latest software, the strcmp function used for checking credentials in httpd, is susceptible to a side-channel attack. By measuring the response time of the httpd process, an attacker could guess each byte of the username and password.

CWE-203CWE-676Jan 11, 2023
CVSS7.5v3.1EPSS0.709%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX