CVE-2021-41451

A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:archer_ax10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_ax10:v1:*:*:*:*:*:*:*

History

14 Feb 2024, 01:17

Type Values Removed Values Added
References () http://ax10v1.com - Not Applicable () http://ax10v1.com - Not Applicable, URL Repurposed

30 Dec 2021, 14:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
First Time Tp-link
Tp-link archer Ax10
Tp-link archer Ax10 Firmware
References (MISC) http://ax10v1.com - (MISC) http://ax10v1.com - Not Applicable
References (MISC) http://tp-link.com - (MISC) http://tp-link.com - Product
References (MISC) https://www.tp-link.com/us/support/download/archer-ax10/v1/#Firmware - (MISC) https://www.tp-link.com/us/support/download/archer-ax10/v1/#Firmware - Product
CPE cpe:2.3:o:tp-link:archer_ax10_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:archer_ax10:v1:*:*:*:*:*:*:*
CWE CWE-444

23 Dec 2021, 22:15

Type Values Removed Values Added
Summary An HTTP/1.1 misconfiguration in web interface of TP-Link AX10v1 before V1_211117 could allow an attacker to send a specially crafted HTTP/0.9 packet that could cause a cache poisoning attack. A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.

17 Dec 2021, 15:41

Type Values Removed Values Added
New CVE

Information

Published : 2021-12-17 15:15

Updated : 2024-02-14 01:17


NVD link : CVE-2021-41451

Mitre link : CVE-2021-41451

CVE.ORG link : CVE-2021-41451


JSON object : View

Products Affected

tp-link

  • archer_ax10_firmware
  • archer_ax10
CWE
CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')