CVE-2021-41451
archer ax10 firmware, archer ax10
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.
- CVSS
- 7.5
- EPSS
- 2.38% 82.3% percentile
- CISA KEV
- Not listed
- Published
- 2021.12.18