CVE Vulnerabilities

CVE-2021-28857

Insufficiently Protected Credentials

Published: Jun 15, 2021 | Modified: Jun 23, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

TP-Links TL-WPA4220 4.0.2 Build 20180308 Rel.37064 username and password are sent via the cookie.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Tl-wpa4220_firmware Tp-link 4.0.2-build_20180308_rel.37064 (including) 4.0.2-build_20180308_rel.37064 (including)

Potential Mitigations

References