TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contains the base64 encoded username and password.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-05-15T13:11:13
Updated: 2024-08-06T03:30:20.291Z
Reserved: 2018-04-05T00:00:00
Link: CVE-2016-10719
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-05-15T14:29:00.453
Modified: 2024-11-21T02:44:35.360
Link: CVE-2016-10719
Redhat
No data.