CVE-2024-37661

MEDIUM

Tp-link Tl-7dr5130 Firmware - Origin Validation Error

Title source: rule
STIX 2.1

Description

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to forged ICMP redirect message attacks. An attacker in the same WLAN as the victim can hijack the traffic between the victim and any remote server by sending out forged ICMP redirect messages.

Scores

CVSS v3 6.3
EPSS 0.0006
EPSS Percentile 19.1%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-346
Status published
Products (1)
tp-link/tl-7dr5130_firmware 1.0.23
Published Jun 17, 2024
Tracked Since Feb 18, 2026