CVE-2024-54126: Insufficient Integrity Verification Vulnerability in TP-Link Archer C50

8.5 CVSS

Description

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.

Classification

CVE ID: CVE-2024-54126

CVSS Base Severity: HIGH

CVSS Base Score: 8.5

Affected Products

Vendor: TP-Link

Product: Archer C50 Wireless Router

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.44% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.cert-in.org.in/s2cMainServlet?pageid=PUBVLNOTES01&VLCODE=CIVN-2024-0354

Timeline