Show filters
169 Total Results
Displaying 91-100 of 169
Sort by:
Attacker Value
Unknown
CVE-2021-29253
Disclosure Date: May 26, 2021 (last updated February 22, 2025)
The Tableau integration in RSA Archer 6.4 P1 (6.4.0.1) through 6.9 P2 (6.9.0.2) is affected by an insecure credential storage vulnerability. An malicious attacker with access to the Tableau workbook file may obtain access to credential information to use it in further attacks.
0
Attacker Value
Unknown
CVE-2020-17891
Disclosure Date: May 14, 2021 (last updated February 22, 2025)
TP-Link Archer C1200 firmware version 1.13 Build 2018/01/24 rel.52299 EU has a XSS vulnerability allowing a remote attacker to execute arbitrary code.
0
Attacker Value
Unknown
CVE-2021-27245
Disclosure Date: March 29, 2021 (last updated February 22, 2025)
This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_200220 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections. The issue results from the lack of proper filtering of IPv6 SSH connections. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-12309.
0
Attacker Value
Unknown
CVE-2021-3275
Disclosure Date: March 26, 2021 (last updated February 22, 2025)
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
0
Attacker Value
Unknown
CVE-2021-27210
Disclosure Date: February 13, 2021 (last updated February 22, 2025)
TP-Link Archer C5v 1.7_181221 devices allows remote attackers to retrieve cleartext credentials via [USER_CFG#0,0,0,0,0,0#0,0,0,0,0,0]0,0 to the /cgi?1&5 URI.
0
Attacker Value
Unknown
CVE-2021-27209
Disclosure Date: February 13, 2021 (last updated February 22, 2025)
In the management interface on TP-Link Archer C5v 1.7_181221 devices, credentials are sent in a base64 format over cleartext HTTP.
0
Attacker Value
Unknown
CVE-2020-29538
Disclosure Date: January 29, 2021 (last updated November 28, 2024)
Archer before 6.9 P1 (6.9.0.1) contains an improper access control vulnerability in an API. A remote authenticated malicious administrative user can potentially exploit this vulnerability to gather information about the system, and may use this information in subsequent attacks.
0
Attacker Value
Unknown
CVE-2020-29537
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Archer before 6.8 P2 (6.8.0.2) is affected by an open redirect vulnerability. A remote privileged attacker may potentially redirect legitimate users to arbitrary web sites and conduct phishing attacks. The attacker could then steal the victims' credentials and silently authenticate them to the Archer application without the victims realizing an attack occurred.
0
Attacker Value
Unknown
CVE-2020-29535
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Archer before 6.8 P4 (6.8.0.4) contains a stored XSS vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.
0
Attacker Value
Unknown
CVE-2020-29536
Disclosure Date: January 29, 2021 (last updated February 22, 2025)
Archer before 6.8 P2 (6.8.0.2) is affected by a path exposure vulnerability. A remote authenticated malicious attacker with access to service files may obtain sensitive information to use it in further attacks.
0