PT-2022-1650 · Tp Link · Tp-Link Tl-Wa850Re
Published
2022-02-17
·
Updated
2023-08-08
·
CVE-2022-22922
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link TL-WA850RE versions prior to v6 200923
Description
The issue is related to the use of highly predictable and easily detectable session keys in the TP-Link TL-WA850RE Wi-Fi Range Extender. This allows attackers to gain administrative privileges. The exploitation of this issue can enable a remote attacker to elevate their privileges.
Recommendations
For versions prior to v6 200923, update to version v6 200923 or later to resolve the issue. As a temporary workaround, consider restricting access to the device to minimize the risk of exploitation.
Exploit
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tp-Link Tl-Wa850Re