CVE-2021-41451
CVE-2021-41451
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 3.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
17 Dec 2021Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A misconfiguration in HTTP/1.0 and HTTP/1.1 of the web interface in TP-Link AX10v1 before V1_211117 allows a remote unauthenticated attacker to send a specially crafted HTTP request and receive a misconfigured HTTP/0.9 response, potentially leading into a cache poisoning attack.
Affected products
n/a · n/aWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →