CVE-2020-10883
HIGHTP-Link Archer A7 Firmware <190726 - Privilege Escalation
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2020-10883.
Includes Metasploit module exploits/linux/misc/tplink_archer_a7_c7_lan_rce.
AI-analyzed exploit summary This Metasploit module exploits a command injection vulnerability in the tdpServer daemon on TP-Link Archer A7/C7 routers, allowing unauthenticated remote code execution as root via UDP port 20002. It includes a checksum calculation for packet validation and supports firmware versions up to 201029/30.
Description
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the file system. The issue lies in the lack of proper permissions set on the file system. An attacker can leverage this vulnerability to escalate privileges. Was ZDI-CAN-9651.
Exploits (2)
This Metasploit module exploits a command injection vulnerability in the tdpServer daemon on TP-Link Archer A7/C7 routers, allowing unauthenticated remote code execution as root via UDP port 20002. It includes a checksum calculation for packet validation and supports firmware versions up to 201029/30.
This Metasploit module exploits a command injection vulnerability in the tdpServer daemon on TP-Link Archer A7/C7 routers, allowing unauthenticated remote code execution as root via a crafted UDP packet on port 20002. The exploit includes a checksum calculation routine and delivers a reverse shell payload.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H