CVE-2020-5797 is a UNIX Symbolic Link Following vulnerability affecting TP-Link Archer C9(US)_V1_180125 firmware. An unauthenticated attacker with physical and network access can exploit this by plugging in a crafted USB drive, allowing them to read sensitive files and write to a limited set of files. Rated Medium (CVSS 6.1), the attack requires physical access but has low complexity and high impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
180125CPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c9_firmware:180125:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020TP-Link Archer Routers USB Symlink Following Vulnerabilities
Nov 5, 2020