Input validation error in Archer C50 V3 - CVE-2020-9375
Published: April 2, 2020 / Updated: April 7, 2020
Vulnerability identifier: #VU26525
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-9375
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can use a specially crafted HTTP Header containing an unexpected Referer field and perform a denial of service (DoS) attack.
Affected software
Archer C50 V3
How to mitigate CVE-2020-9375
Install updates from vendor's website.
Archer C50 V3 - update to 20200226
Links to Public Exploits and PoC-codes
- Exploit #2280 - Exploits (Containing Self Made Perl Reproducers / PoC Codes) (April 7, 2020)
- Exploit #2257 - cve-2020-9375 (TP-Link Archer C50 V3 devices before Build 200318 Rel. 62209 allows remote attackers to cause a denial of service via a crafted HTTP Header containing an unexpected Referer field.) (April 3, 2020)