TP-Link Archer AX55 v4 的 Web 模块中存在硬编码加密密钥漏洞。局域网(LAN)攻击者若捕获了 HTTP 登录会话,可利用已知的共享 RSA 私钥解密管理员密码;而强度较弱的 AES 会话密钥进一步降低了破坏会话机密性所需的努力程度。 成功利用该漏洞可能泄露从 HTTP 登录会话中捕获的管理员密码,并破坏会话的机密性。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| TP-Link Systems Inc. | Archer AX55 v4 | 0 ~ 1.2.1 Build 20260527 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet