CVE-2020-10883: (Pwn2Own) TP-Link Archer A7 File System Incorrect Permission Assignment for Critical Resource Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the file system. The issue lies in the lack of proper permissions set on the file system. An attacker can leverage this vulnerability to escalate privileges.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the file system. The issue lies in the lack of proper permissions set on the file system. An attacker can leverage this vulnerability to escalate privileges. Was ZDI-CAN-9651.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-10883.
What is the severity of CVE-2020-10883?
The severity of CVE-2020-10883 is high with a score of 7.8.
What is the affected software of CVE-2020-10883?
The affected software of CVE-2020-10883 is TP-Link Archer A7 Firmware Ver: 190726 AC1750 routers.
How can an attacker exploit CVE-2020-10883?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Are there any known fixes for CVE-2020-10883?
Always keep your router firmware up to date to mitigate the risk of this vulnerability.