CVE-2020-5795: High severity TP-Link Archer A7 Firmware vulnerability
Published Nov 6, 2020
·Updated
UNIX Symbolic Link (Symlink) Following in TP-Link Archer A7(US)V5200721 allows an authenticated admin user, with physical access and network access, to execute arbitrary code after plugging a crafted USB drive into the router.
Affected Software
2 affected components
TP-Link Archer A7 Firmware=200721
TP-Link Archer A7=v5
Event History
Nov 6, 2020
CVE Published
via MITRE·02:09 PM
Data Sourced
via MITRE·02:09 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-5795.
2
What is the severity of CVE-2020-5795?
The severity of CVE-2020-5795 is high.
3
Which software is affected by CVE-2020-5795?
TP-Link Archer A7 Firmware version 200721 is affected by CVE-2020-5795.
4
How can an attacker exploit CVE-2020-5795?
An attacker with physical and network access can exploit CVE-2020-5795 by plugging a crafted USB drive into the router.
5
Is TP-Link Archer A7 v5 vulnerable to CVE-2020-5795?
No, TP-Link Archer A7 v5 is not vulnerable to CVE-2020-5795.