CVE-2016-1000009 describes a vulnerability where TP-Link lost control of the domains www.tplinklogin.net and tplinkextender.net, which are physically printed on many of their devices. This presents a high-severity risk (CVSS 7.5) due to an unauthenticated network attack that could lead to high integrity impact, potentially allowing an attacker to redirect users to malicious sites. While no active exploitation, public exploit code, or significant community discussion has been observed, the inherent risk remains due to the potential for domain hijacking and subsequent user compromise.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:tp-link:tp-link:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.