ZDI-23-452: (Pwn2Own) TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability
This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-452?
The ZDI-23-452 vulnerability is classified as a high severity issue due to its potential for remote exploitation without authentication.
How do I fix ZDI-23-452?
To fix ZDI-23-452, users should update their TP-Link Archer AX21 routers to the latest firmware version provided by the vendor.
What impact does ZDI-23-452 have on my TP-Link Archer AX21 router?
ZDI-23-452 allows remote attackers to access LAN-side services, potentially compromising the security of the entire network.
Is authentication required to exploit ZDI-23-452?
No, authentication is not required to exploit the ZDI-23-452 vulnerability, making it particularly dangerous.
Who is affected by ZDI-23-452?
The ZDI-23-452 vulnerability affects users of TP-Link Archer AX21 routers that have not been updated to mitigate the vulnerability.