PT-2022-1650 · Tp Link · Tp-Link Tl-Wa850Re

Published

2022-02-17

·

Updated

2023-08-08

·

CVE-2022-22922

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link TL-WA850RE versions prior to v6 200923
Description The issue is related to the use of highly predictable and easily detectable session keys in the TP-Link TL-WA850RE Wi-Fi Range Extender. This allows attackers to gain administrative privileges. The exploitation of this issue can enable a remote attacker to elevate their privileges.
Recommendations For versions prior to v6 200923, update to version v6 200923 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.

Exploit

Fix

Use of Insufficiently Random Values

Weakness Enumeration

Related Identifiers

BDU:2022-00900
CVE-2022-22922

Affected Products

Tp-Link Tl-Wa850Re