TP-Link’s TL-WPA4220 V4.0 Cleartext Credentials in Cookie
Mar 15, 2021
Model: TL-WPA4220
Firmware: 4.0.2 Build 20180308 Rel.37064
Hardware: Version: TL-WPA4220 v4.0
CVE: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28857
TP-Link’s TL-WPA4220 V4.0 username and password are sent via the cookie.
The password is sent as md5.
If an attacker cracks the md5, attacker may log in existing router interface.