Security Advisory

CVE-2024-54126

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-12-05 12:14:41
Last updated 2024-12-05 16:37:56
Assigner CERT-In
State PUBLISHED

Description

This vulnerability exists in the TP-Link Archer C50 due to improper signature verification mechanism in the firmware upgrade process at its web interface. An attacker with administrative privileges within the router’s Wi-Fi range could exploit this vulnerability by uploading and executing malicious firmware which could lead to complete compromise of the targeted device.