CVE-2024-37662

MEDIUM

TP-LINK TL-7DR5130 v1.0.23 - TCP Denial of Service or Traffic Hijacking via Forged RST Messages

Title source: llm
STIX 2.1

Description

TP-LINK TL-7DR5130 v1.0.23 is vulnerable to TCP DoS or hijacking attacks. An attacker in the same WLAN as the victim can disconnect or hijack the traffic between the victim and any remote server by sending out forged TCP RST messages to evict NAT mappings in the router.

Scores

CVSS v3 6.3
EPSS 0.0038
EPSS Percentile 29.7%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-940
Status published
Products (1)
tp-link/tl-7dr5130_firmware 1.0.23
Published Jun 17, 2024
Tracked Since Feb 18, 2026