First published: Wed Mar 15 2023(Updated: )
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer AX21 routers. Authentication is not required to exploit this vulnerability.
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link Archer AX21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
ZDI-CAN-19898 has been classified as a critical vulnerability due to its ability to allow arbitrary code execution without authentication.
To mitigate ZDI-CAN-19898, users should update their TP-Link Archer AX21 routers to the latest firmware version provided by TP-Link.
ZDI-CAN-19898 affects installations of TP-Link Archer AX21 routers that have not been updated to the latest firmware.
Attackers can exploit ZDI-CAN-19898 remotely from a network-adjacent position to execute arbitrary code on the affected router.
No, ZDI-CAN-19898 does not require authentication for exploitation, making it particularly dangerous.