PT-2021-18166 · Tp Link · Tp-Link Tl-Wr802N+1

Published

2021-04-12

·

Updated

2021-04-21

·

CVE-2021-29302

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: TP-Link TL-WR802N(US) versions prior to 2020.06 Archer C50v5 US version 4 200 or earlier
Description: The issue is related to a buffer overflow in the httpd process, specifically in the body message. This can be exploited by an attacker sending a crafted message through the network, potentially leading to remote code execution and allowing the attacker to gain shell access to the router.
Recommendations: For TP-Link TL-WR802N(US) versions prior to 2020.06, update to a version released after 2020.06 to resolve the issue. For Archer C50v5 US version 4 200 or earlier, update to a version later than 4 200 to fix the problem. As a temporary workaround, consider restricting network access to the router until a patch is applied.

Exploit

Fix

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-29302

Affected Products

Archer C50
Tp-Link Tl-Wr802N