CVE-2021-3125

In TP-Link TL-XDR3230 < 1.0.12, TL-XDR1850 < 1.0.9, TL-XDR1860 < 1.0.14, TL-XDR3250 < 1.0.2, TL-XDR6060 Turbo < 1.1.8, TL-XDR5430 < 1.0.11, and possibly others, when IPv6 is used, a routing loop can occur that generates excessive network traffic between an affected device and its upstream ISP's router. This occurs when a link prefix route points to a point-to-point link, a destination IPv6 address belongs to the prefix and is not a local IPv6 address, and a router advertisement is received with at least one global unique IPv6 prefix for which the on-link flag is set.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr3230_firmware:*:*:*:*:*:easy_exhibition_turbo:*:*
cpe:2.3:h:tp-link:tl-xdr3230:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr5430_firmware:*:*:*:*:*:easy_exhibition:*:*
cpe:2.3:h:tp-link:tl-xdr5430:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr3250_firmware:*:*:*:*:*:easy_exhibition:*:*
cpe:2.3:h:tp-link:tl-xdr3250:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr1860_firmware:*:*:*:*:*:easy_exhibition:*:*
cpe:2.3:h:tp-link:tl-xdr1860:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr1850_firmware:*:*:*:*:*:easy_exhibition:*:*
cpe:2.3:h:tp-link:tl-xdr1850:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tp-link:tl-xdr6060_firmware:*:*:*:*:*:easy_exhibition:*:*
cpe:2.3:h:tp-link:tl-xdr6060:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2021-04-12 19:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-3125

Mitre link : CVE-2021-3125

CVE.ORG link : CVE-2021-3125


JSON object : View

Products Affected

tp-link

  • tl-xdr1850_firmware
  • tl-xdr1850
  • tl-xdr3250
  • tl-xdr3230_firmware
  • tl-xdr6060
  • tl-xdr3250_firmware
  • tl-xdr6060_firmware
  • tl-xdr1860_firmware
  • tl-xdr5430_firmware
  • tl-xdr3230
  • tl-xdr5430
  • tl-xdr1860
CWE
CWE-834

Excessive Iteration