CVE-2024-54126 - CVE House
Back to Database
Status published High CVE-2024-54126

Insufficient Integrity Verification Vulnerability in TP-Link Archer C50

Vulnerability Description

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-54126

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability is reported is reported by Khalid Markar, Amey Chavekar, Sushant Mane & Dr. Faruk Kazi from CoE-CNDS Lab, VJTI, Mumbai

Affected Vendor

Affected Software

Archer C50 Wireless Router
Vulnerable Versions:
<Archer C50(EU)_V4_ 240917

Timeline

Official Publish: December 5th, 2024
Last Modified: December 5th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)