ZDI-CAN-19664: ZDI-23-452: (Pwn2Own) TP-Link AX1800 hotplugd Firewall Rule Race Condition Vulnerability
Published Apr 24, 2023
·Updated
This vulnerability allows remote attackers to gain access to LAN-side services on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.
Affected Software
1 affected component
TP-Link AX1800
Event History
Apr 24, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Jan 20, 2025
Advisory Published
via ZDI·05:12 AM
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19664?
The severity of ZDI-CAN-19664 is classified as high due to its ability for remote attackers to access LAN services without authentication.
2
How do I fix ZDI-CAN-19664?
To fix ZDI-CAN-19664, update your TP-Link Archer AX21 router to the latest firmware version provided by TP-Link.
3
What devices are affected by ZDI-CAN-19664?
ZDI-CAN-19664 affects the TP-Link Archer AX21 routers.
4
Is authentication required to exploit ZDI-CAN-19664?
No, authentication is not required to exploit ZDI-CAN-19664, making it particularly dangerous.
5
What type of attack does ZDI-CAN-19664 enable?
ZDI-CAN-19664 enables remote attackers to gain unauthorized access to LAN-side services on vulnerable router installations.