CVE-2021-31658
Published on: 06/10/2021 12:00:00 AM UTC
Last Modified on: 06/23/2021 02:54:00 PM UTC
Certain versions of Tl-sg2005 from Tp-link contain the following vulnerability:
TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.
- CVE-2021-31658 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
CVSS3 Score: 8.1 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | HIGH | HIGH |
CVSS2 Score: 5.8 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
CVE/2021/CVE-2021-31658 at main · liyansong2018/CVE · GitHub | github.com text/html |
![]() |
TP-Link Canada - WiFi Networking Equipment for Home & Business | tp-link.com text/html |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Tp-link | Tl-sg2005 | - | All | All | All |
Operating System | Tp-link | Tl-sg2005 Firmware | 1.0.0 | build_20180529_rel.40524 | All | All |
Hardware
| Tp-link | Tl-sg2008 | - | All | All | All |
Operating System | Tp-link | Tl-sg2008 Firmware | 1.0.0 | build_20180529_rel.40524 | All | All |
- cpe:2.3:h:tp-link:tl-sg2005:-:*:*:*:*:*:*:*:
- cpe:2.3:o:tp-link:tl-sg2005_firmware:1.0.0:build_20180529_rel.40524:*:*:*:*:*:*:
- cpe:2.3:h:tp-link:tl-sg2008:-:*:*:*:*:*:*:*:
- cpe:2.3:o:tp-link:tl-sg2008_firmware:1.0.0:build_20180529_rel.40524:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-31658 : TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index er… twitter.com/i/web/status/1… | 2021-06-10 15:10:14 |
![]() |
CVE-2021-31658 | 2021-06-10 15:41:54 |