← Back

CVE-2021-27245

nvd nist
Published: Mar 29, 2021Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

This vulnerability allows a firewall bypass on affected installations of TP-Link Archer A7 prior to Archer C7(US)_V5_210125 and Archer A7(US)_V5_200220 AC1750 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of IPv6 connections. The issue results from the lack of proper filtering of IPv6 SSH connections. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of root. Was ZDI-CAN-12309.

Affected (2)

1 product
Archer A7 Firmware
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before c7\(us\)_v5_210125
Configuration B
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Before a7\(us\)_v5_200220
Running on/withPlatform Versions
Tp Link
Archer A7
All versions

References (2)

Source: zdi-disclosures@trendmicro.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.