Cross-Site Scripting vulnerability in TP-Link Archer AX50
Vulnerability Description
Cross-Site Scripting (XSS) vulnerability stored in TP-Link Archer AX50 affecting firmware version 1.0.11 build 2022052. This vulnerability could allow an unauthenticated attacker to create a port mapping rule via a SOAP request and store a malicious JavaScript payload within that rule, which could result in an execution of the JavaScript payload when the rule is loaded.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-2188
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Victor Fresco Perales (@hacefresko)
More from TP-Link
View All →Affected Vendor
TP-Link
View all reports →