Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2024-57049 PoC — TP-LINK Archer C20 安全漏洞

Source
Associated Vulnerability
Title:TP-LINK Archer C20 安全漏洞 (CVE-2024-57049)
Description:TP-LINK Archer C20是中国普联(TP-LINK)公司的一款路由器。 TP-LINK Archer C20 V6.6_230412版本及之前版本存在安全漏洞。攻击者利用该漏洞可以在请求中添加Referer: http://tplinkwifi.net,即可识别为通过认证。
Description
A vulnerability in the TP-Link Archer C20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass authentication on interfaces under the /cgi directory. When adding a Referer header with value "http://tplinkwifi.net" to requests, the router will recognize the request as passing authentication, allowing access to protected administration interfaces.
File Snapshot

id: CVE-2024-57049 info: name: TP-Link Archer C20 - Authentication Bypass author: ritikchaddha ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.