CVE-2016-10719
Severity CVSS v4.0:
Pending analysis
Type:
CWE-79
Cross-Site Scripting (XSS)
Publication date:
15/05/2019
Last modified:
16/05/2019
Description
TP-Link Archer CR-700 1.0.6 devices have an XSS vulnerability that can be introduced into the admin account through a DHCP request, allowing the attacker to steal the cookie information, which contains the base64 encoded username and password.
Impact
Base Score 3.x
6.10
Severity 3.x
MEDIUM
Base Score 2.0
4.30
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:archer_cr700_firmware:1.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:archer_cr700:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



