Description
An issue in TP-Link AX10 Ax1500 v.1.3.10 Build (20230130) allows a remote attacker to obtain sensitive information
References (2)
Core 2
Core References
Various Sources
https://intrix.com.au/articles/exposing-insecure-http-basic-authentication-tp-link-archer-ax10-cwe-id-cwe-319/
Various Sources
https://www.linkedin.com/in/timothy-hoekstra-91b6951b2
Scores
CVSS v3
7.5
EPSS
0.0046
EPSS Percentile
36.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CISA SSVC
Vulnrichment
Exploitation
poc
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Published
Sep 09, 2025
Tracked Since
Feb 18, 2026