CVE Vulnerabilities

CVE-2021-28858

Cleartext Storage of Sensitive Information

Published: Jun 15, 2021 | Modified: Nov 21, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
2.1 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

TP-Links TL-WPA4220 4.0.2 Build 20180308 Rel.37064 does not use SSL by default. Attacker on the local network can monitor traffic and capture the cookie and other sensitive information.

Weakness

The product stores sensitive information in cleartext within a resource that might be accessible to another control sphere.

Affected Software

Name Vendor Start Version End Version
Tl-wpa4220_firmware Tp-link 4.0.2-build_20180308_rel.37064 (including) 4.0.2-build_20180308_rel.37064 (including)

Potential Mitigations

References