TP-LINK Archer A20是中国普联(TP-LINK)公司的一款路由器。 TP-LINK Archer A20 v3版本存在安全漏洞,该漏洞源于Web界面对目录列表路径处理不当。攻击者利用该漏洞可以将恶意代码注入页面,在受害者的浏览器上执行JavaScript。
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|---|---|---|
| 1 | None | https://github.com/rvizx/CVE-2024-57514 | POC详情 |
| 2 | The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (XSS) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2024/CVE-2024-57514.yaml | POC详情 |
未找到公开 POC。
登录以生成 AI POC| CVE-2025-22217 | 8.6 HIGH | VMware Avi Load Balancer 安全漏洞 |
| CVE-2024-11954 | 2.4 LOW | Pimcore 安全漏洞 |
| CVE-2025-22917 | Audemium ERP 安全漏洞 | |
| CVE-2024-48310 | AutoLib Software Systems OPAC 安全漏洞 | |
| CVE-2024-55968 | DTEX DEC-M 安全漏洞 | |
| CVE-2024-56529 | mailcow 安全漏洞 | |
| CVE-2024-57519 | Open5GS 安全漏洞 | |
| CVE-2024-57376 | D-Link多款产品 安全漏洞 |
暂无评论