CVE-2021-40288: High severity tp-link ax10 firmware vulnerability
A denial-of-service attack in WPA2, and WPA3-SAE authentication methods in TP-Link AX10v1 before V1211014, allows a remote unauthenticated attacker to disconnect an already connected wireless client via sending with a wireless adapter specific spoofed authentication frames
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2021-40288?
CVE-2021-40288 is a denial-of-service vulnerability in the WPA2 and WPA3-SAE authentication methods in TP-Link AX10v1 before V1_211014.
How does CVE-2021-40288 affect TP-Link AX10v1?
CVE-2021-40288 allows a remote unauthenticated attacker to disconnect an already connected wireless client by sending spoofed authentication frames with a specific wireless adapter.
What is the severity of CVE-2021-40288?
CVE-2021-40288 has a severity rating of 7.5 (high).
Which software versions of TP-Link AX10v1 are affected by CVE-2021-40288?
TP-Link AX10v1 before V1_211014 is affected by CVE-2021-40288.
How can I fix CVE-2021-40288?
To fix CVE-2021-40288, update your TP-Link AX10v1 firmware to V1_211014 or later.