CVE-2024-54127 - CVE House
Back to Database
Status published Medium CVE-2024-54127

Exposure of Wi-Fi Credentials in Plaintext in TP-Link Archer C50

Vulnerability Description

This vulnerability exists in the TP-Link Archer C50 due to presence of terminal access on a serial interface without proper access control. An attacker with physical access could exploit this by accessing the UART shell on the vulnerable device. Successful exploitation of this vulnerability could allow the attacker to obtain Wi-Fi credentials of the targeted system.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-54127

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • This vulnerability is reported is reported by Amey Chavekar, Khalid Markar & Dr. Faruk Kazi from CoE-CNDS Lab, VJTI, Mumbai

Affected Vendor

Affected Software

Archer C50 Wireless Router
Vulnerable Versions:
<Archer C50(EU)_V4_ 240917

Timeline

Official Publish: December 5th, 2024
Last Modified: December 5th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)