CVE-2021-3275: XSS
Unauthenticated stored cross-site scripting (XSS) exists in multiple TP-Link products including WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, which affects TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices through the improper validation of the hostname. Some of the pages including dhcp.htm, networkMap.htm, dhcpClient.htm, qsEdit.htm, and qsReview.htm and use this vulnerable hostname function (setDefaultHostname()) without sanitization.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-3275?
CVE-2021-3275 is an unauthenticated stored cross-site scripting (XSS) vulnerability that exists in multiple TP-Link products.
Which TP-Link products are affected by CVE-2021-3275?
CVE-2021-3275 affects TP-Link WIFI Routers (Wireless AC routers), Access Points, ADSL + DSL Gateways and Routers, including TD-W9977v1, TL-WA801NDv5, TL-WA801Nv6, TL-WA802Nv5, and Archer C3150v2 devices.
What is the severity of CVE-2021-3275?
CVE-2021-3275 has a severity rating of 6.1, which is considered medium.
How does CVE-2021-3275 affect TP-Link products?
CVE-2021-3275 allows for unauthenticated stored cross-site scripting (XSS) attacks on affected TP-Link products.
Are there any references for CVE-2021-3275?
Yes, you can find more information about CVE-2021-3275 at the following references: [1] [2] [3]