PT-2021-18166 · Tp Link · Tp-Link Tl-Wr802N+1
Published
2021-04-12
·
Updated
2021-04-21
·
CVE-2021-29302
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
TP-Link TL-WR802N(US) versions prior to 2020.06
Archer C50v5 US version 4 200 or earlier
Description:
The issue is related to a buffer overflow in the httpd process, specifically in the body message. This can be exploited by an attacker sending a crafted message through the network, potentially leading to remote code execution and allowing the attacker to gain shell access to the router.
Recommendations:
For TP-Link TL-WR802N(US) versions prior to 2020.06, update to a version released after 2020.06 to resolve the issue.
For Archer C50v5 US version 4 200 or earlier, update to a version later than 4 200 to fix the problem.
As a temporary workaround, consider restricting network access to the router until a patch is applied.
Exploit
Fix
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Archer C50
Tp-Link Tl-Wr802N