CVE-2024-57514: TP-Link Archer A20 v3 Router – Cross-site Scripting

CVE-2024-57514: TP-Link Archer A20 v3 Router - Cross-site Scripting-渗透云记 - 专注于网络安全与技术分享
CVE-2024-57514: TP-Link Archer A20 v3 Router – Cross-site Scripting
此内容为付费阅读,请付费后查看
100积分
付费阅读

漏洞标题

CVE-2024-57514: TP-Link Archer A20 v3 Router – Cross-site Scripting

漏洞描述

The TP-Link Archer A20 v3 router is vulnerable to Cross-site Scripting (xss) due to improper handling of directory listing paths in the web interface. When a specially crafted URL is visited, the router's web page renders the directory listing and executes arbitrary JavaScript embedded in the URL. This allows the attacker to inject malicious code into the page, executing JavaScript on the victim's browser, which could then be used for further malicious actions. The vulnerability was identified in the 1.0.6 Build 20231011 rel.85717(5553) version.

PoC代码

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享