A vulnerability in TP-Link Archer C50 V3 devices prior to Build 200318 Rel. 62209 allows remote attackers to trigger a denial of service condition by sending an HTTP request with a specially crafted Referer header. The device's HTTP server does not properly handle unexpected or malformed Referer fields, leading to a crash or service disruption.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a proof-of-concept exploit for CVE-2020-9375, targeting TP-Link Archer C50 v3 routers (Build 171227). The exploit consists of a single Python script (exploit.py) and a README.md file. The script attempts to cause a denial of service by sending a specially crafted HTTP GET request to the router's web interface at 192.168.0.1:80. The request includes a non-standard 'Referer' header, which triggers the vulnerability and can make the device unresponsive. The exploit is simple, does not require authentication, and is intended for demonstration purposes. The README provides background, references, and usage information. No external frameworks are used, and the exploit is self-contained.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.