CRITICAL

CVE-2020-35575

CVSS v3

9.8

CRITICAL

EPSS Score

18.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Technical details

Published
12/26/2020

Frequently asked questions

What is CVE-2020-35575?

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Is CVE-2020-35575 actively exploited?

Active exploitation of CVE-2020-35575 has not been confirmed. The EPSS score is 18.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-35575?

CVE-2020-35575 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2020-35575 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.