CVE-2022-41541

HIGH

TP-Link AX10v1 - Open Redirect

Title source: llm

Description

TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application as an admin user.

Scores

CVSS v3 8.1
EPSS 0.0088
EPSS Percentile 75.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-294
Status published

Affected Products (1)

tp-link/ax10_firmware

Timeline

Published Oct 18, 2022
Tracked Since Feb 18, 2026