// For flags

CVE-2021-3125

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, and possibly others, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.

En TP-Link TL-XDR3230 versiones anteriores a 1.0.12, TL-XDR1850 versiones anteriores a 1.0.9, TL-XDR1860 versiones anteriores a 1.0.14, TL-XDR3250 versiones anteriores a 1.0.2, TL-XDR6060 Turbo versiones anteriores a 1.1.8, TL-XDR5430 versiones anteriores a 1.0 .11, y posiblemente otros, cuando se utiliza IPv6, puede producirse un bucle de enrutamiento que genere un tráfico de red excesivo entre un dispositivo afectado y el enrutador de su ISP aguas arriba. Esto ocurre cuando una ruta de prefijo de enlace apunta a un enlace punto a punto, una dirección IPv6 de destino pertenece al prefijo y no es una dirección IPv6 local, y un anuncio de enrutador es recibido con al menos un prefijo IPv6 único global para el cual el flag on-link se establece

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2021-01-11 CVE Reserved
  • 2021-04-12 CVE Published
  • 2023-12-27 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-834: Excessive Iteration
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Tp-link
Search vendor "Tp-link"
Tl-xdr3230 Firmware
Search vendor "Tp-link" for product "Tl-xdr3230 Firmware"
< 1.0.12
Search vendor "Tp-link" for product "Tl-xdr3230 Firmware" and version " < 1.0.12"
easy_exhibition_turbo
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr3230
Search vendor "Tp-link" for product "Tl-xdr3230"
--
Safe
Tp-link
Search vendor "Tp-link"
Tl-xdr5430 Firmware
Search vendor "Tp-link" for product "Tl-xdr5430 Firmware"
< 1.0.11
Search vendor "Tp-link" for product "Tl-xdr5430 Firmware" and version " < 1.0.11"
easy_exhibition
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr5430
Search vendor "Tp-link" for product "Tl-xdr5430"
--
Safe
Tp-link
Search vendor "Tp-link"
Tl-xdr3250 Firmware
Search vendor "Tp-link" for product "Tl-xdr3250 Firmware"
< 1.0.2
Search vendor "Tp-link" for product "Tl-xdr3250 Firmware" and version " < 1.0.2"
easy_exhibition
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr3250
Search vendor "Tp-link" for product "Tl-xdr3250"
--
Safe
Tp-link
Search vendor "Tp-link"
Tl-xdr1860 Firmware
Search vendor "Tp-link" for product "Tl-xdr1860 Firmware"
< 1.0.14
Search vendor "Tp-link" for product "Tl-xdr1860 Firmware" and version " < 1.0.14"
easy_exhibition
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr1860
Search vendor "Tp-link" for product "Tl-xdr1860"
--
Safe
Tp-link
Search vendor "Tp-link"
Tl-xdr1850 Firmware
Search vendor "Tp-link" for product "Tl-xdr1850 Firmware"
< 1.0.9
Search vendor "Tp-link" for product "Tl-xdr1850 Firmware" and version " < 1.0.9"
easy_exhibition
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr1850
Search vendor "Tp-link" for product "Tl-xdr1850"
--
Safe
Tp-link
Search vendor "Tp-link"
Tl-xdr6060 Firmware
Search vendor "Tp-link" for product "Tl-xdr6060 Firmware"
< 1.1.8
Search vendor "Tp-link" for product "Tl-xdr6060 Firmware" and version " < 1.1.8"
easy_exhibition
Affected
in Tp-link
Search vendor "Tp-link"
Tl-xdr6060
Search vendor "Tp-link" for product "Tl-xdr6060"
--
Safe