CVE Feed

    Dashboard / CVE / CVE-2022-41540

    CVE-2022-41540

    The web app client of TP-Link AX10v1 V1_211117 uses hard-coded cryptographic keys when communicating with the router. Attackers who are able to intercept the communications between the web client and router through a man-in-the-middle attack can then obtain the sequence key via a brute-force attack, and access sensitive information.

    Published:Oct 18, 2022
    Last Modified:May 15, 2025
    EPS:Oct 18, 2022
    EPSS Score:0.03239
    CVSS Score:5.9

    Affected Products

    Vendor
    Tp-link
    Product
    Ax10
    Vendor
    Tp-link
    Product
    Ax10 Firmware

    Common Weakness Enumeration

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High