Vulnerability Description
An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Archer Ax10 V1 Firmware | < 211117 |
| Tp-Link | Archer Ax10 V1 | - |
Related Weaknesses (CWE)
References
- http://ax10v1.comBroken LinkURL Repurposed
- http://tp-link.comVendor Advisory
- https://www.tp-link.com/us/support/download/archer-ax10/v1/#FirmwareRelease NotesVendor Advisory
- http://ax10v1.comBroken LinkURL Repurposed
- http://tp-link.comVendor Advisory
- https://www.tp-link.com/us/support/download/archer-ax10/v1/#FirmwareRelease NotesVendor Advisory
FAQ
What is CVE-2021-41450?
CVE-2021-41450 is a vulnerability with a CVSS score of 7.5 (HIGH). An HTTP request smuggling attack in TP-Link AX10v1 before v1_211117 allows a remote unauthenticated attacker to DoS the web application via sending a specific HTTP packet.
How severe is CVE-2021-41450?
CVE-2021-41450 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-41450?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Archer Ax10 V1 Firmware, Tp-Link Archer Ax10 V1.