peter bassill · operator
$ cve CVE-2020-35575 JSON

CVE-2020-35575

9.8
CRITICAL · CVSS 3.1 · EPSS 7.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

A password-disclosure issue in the web interface on certain TP-Link devices allows a remote attacker to get full administrative access to the web panel. This affects WA901ND devices before 3.16.9(201211) beta, and Archer C5, Archer C7, MR3420, MR6400, WA701ND, WA801ND, WDR3500, WDR3600, WE843N, WR1043ND, WR1045ND, WR740N, WR741ND, WR749N, WR802N, WR840N, WR841HP, WR841N, WR842N, WR842ND, WR845N, WR940N, WR941HP, WR945N, WR949N, and WRD4300 devices.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.64% — more likely to be exploited than 94% of all CVEs
On CISA KEVno
Public exploitnone known
Published2020-12-26
Last modified2026-06-17

Affected (40)

VendorProduct
tp-linkarcher c5
tp-linkarcher c5 firmware
tp-linkarcher c7
tp-linkarcher c7 firmware
tp-linkmr3420
tp-linkmr3420 firmware
tp-linkmr6400
tp-linkmr6400 firmware
tp-linkwa701nd
tp-linkwa701nd firmware
tp-linkwa801nd
tp-linkwa801nd firmware
tp-linkwa901nd
tp-linkwa901nd firmware
tp-linkwdr3500
tp-linkwdr3500 firmware
tp-linkwdr3600
tp-linkwdr3600 firmware
tp-linkwe843n
tp-linkwe843n firmware
tp-linkwr1043nd
tp-linkwr1043nd firmware
tp-linkwr1045nd
tp-linkwr1045nd firmware
tp-linkwr740n
tp-linkwr740n firmware
tp-linkwr741nd
tp-linkwr741nd firmware
tp-linkwr749n
tp-linkwr749n firmware
tp-linkwr802n
tp-linkwr802n firmware
tp-linkwr840n
tp-linkwr840n firmware
tp-linkwr841hp
tp-linkwr841hp firmware
tp-linkwr841n
tp-linkwr841n firmware
tp-linkwr842n
tp-linkwr842n firmware

References

→ the Explorer  ·  watch your stack  ·  NVD