mirror of
https://github.com/0xMarcio/cve.git
synced 2026-05-10 20:04:58 +02:00
799 B
799 B
CVE-2017-11519
Description
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.
POC
Reference
- https://devcraft.io/posts/2017/07/21/tp-link-archer-c9-admin-password-reset.html
- https://devcraft.io/posts/2017/07/21/tp-link-archer-c9-admin-password-reset.html