CVE-2019-13268

HIGH

TP-Link Archer C3200 V1 and Archer C2 V1 Firmware - ARP Request Forwarding Between Host and Guest Networks

Title source: llm
STIX 2.1

Description

TP-Link Archer C3200 V1 and Archer C2 V1 devices have Insufficient Compartmentalization between a host network and a guest network that are established by the same device. They forward ARP requests, which are sent as broadcast packets, between the host and the guest networks. To use this leakage as a direct covert channel, the sender can trivially issue an ARP request to an arbitrary computer on the network. (In general, some routers restrict ARP forwarding only to requests destined for the network's subnet mask, but these routers did not restrict this traffic in any way. Depending on this factor, one must use either the lower 8 bits of the IP address, or the entire 32 bits, as the data payload.)

References (2)

Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://orenlab.sise.bgu.ac.il/publications/CrossRouter
Third Party Advisory x_refsource_misc
https://www.usenix.org/system/files/woot19-paper_ovadia.pdf

Scores

CVSS v3 8.8
EPSS 0.0011
EPSS Percentile 29.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-20
Status published
Products (2)
tp-link/archer_c2_v1_firmware
tp-link/archer_c3200_v1_firmware
Published Aug 27, 2019
Tracked Since Feb 18, 2026