Vulnerability Description
Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Archer Ax50 Firmware | 1.0.11 |
| Tp-Link | Archer Ax50 | - |
Related Weaknesses (CWE)
References
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
- https://www.incibe.es/en/incibe-cert/notices/aviso/cross-site-scripting-vulnerabThird Party Advisory
FAQ
What is CVE-2024-2188?
CVE-2024-2188 is a vulnerability with a CVSS score of 6.1 (MEDIUM). Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapp...
How severe is CVE-2024-2188?
CVE-2024-2188 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-2188?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Archer Ax50 Firmware, Tp-Link Archer Ax50.