漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
This vulnerability allows network-adjacent attackers to escalate privileges on affected installations of TP-Link TL-WA855RE Firmware Ver: 855rev4-up-ver1-0-1-P1[20191213-rel60361] Wi-Fi extenders. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the first-time setup process. The issue results from the lack of proper validation on first-time setup requests. An attacker can leverage this vulnerability to reset the password for the Admin account and execute code in the context of the device. Was ZDI-CAN-10003.
CVSS Information
N/A
Vulnerability Type
认证机制不恰当
Vulnerability Title
TP-Link TL-WA855RE 授权问题漏洞
Vulnerability Description
TP-Link TL-WA855RE是中国普联(TP-Link)公司的一款无线网络信号扩展器。 使用855rev4-up-ver1-0-1-P1[20191213-rel60361]版本固件的TP-Link TL-WA855RE中的初次设置进程存在授权问题漏洞,该漏洞源于程序没有正确验证初次设置的请求。攻击者可利用该漏洞重置Admin账户密码,执行代码。
CVSS Information
N/A
Vulnerability Type
N/A