CVE-2022-41541

HIGH

TP-Link AX10v1 - Open Redirect

Title source: llm
STIX 2.1

Description

TP-Link AX10v1 V1_211117 allows attackers to execute a replay attack by using a previously transmitted encrypted authentication message and valid authentication token. Attackers are able to login to the web application as an admin user.

Scores

CVSS v3 8.1
EPSS 0.0088
EPSS Percentile 75.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-294
Status published
Products (1)
tp-link/ax10_firmware v1_211117
Published Oct 18, 2022
Tracked Since Feb 18, 2026