TP-Link TL-SG2005, TL-SG2008, etc. 1.0.0 Build 20180529 Rel.40524 is affected by an Array index error. The interface that provides the "device description" function only judges the length of the received data, and does not filter special characters. This vulnerability will cause the application to crash, and all device configuration information will be erased.
                
            References
                    | Link | Resource | 
|---|---|
| http://tp-link.com | Vendor Advisory | 
| https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658 | Exploit Third Party Advisory | 
| http://tp-link.com | Vendor Advisory | 
| https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-31658 | Exploit Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
 
 | 
Configuration 2 (hide)
| AND | 
 
 | 
History
                    No history.
Information
                Published : 2021-06-10 15:15
Updated : 2024-11-21 06:06
NVD link : CVE-2021-31658
Mitre link : CVE-2021-31658
CVE.ORG link : CVE-2021-31658
JSON object : View
Products Affected
                tp-link
- tl-sg2005_firmware
- tl-sg2005
- tl-sg2008_firmware
- tl-sg2008
CWE
                
                    
                        
                        CWE-129
                        
            Improper Validation of Array Index
