PT-2022-2269 · Tp Link · Tp-Link Wr-886N

Published

2022-03-09

·

Updated

2022-03-12

·

CVE-2021-44629

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-LINK WR-886N version 2.3.8
Description A Buffer Overflow issue exists in the /cloud config/router post/register feature, allowing malicious users to execute arbitrary code on the system via a crafted post request. The vulnerability is caused by a buffer overflow on the stack, which can be exploited by a remote attacker using a specially formed request.
Recommendations For TP-LINK WR-886N version 2.3.8, as a temporary workaround, consider disabling the /cloud config/router post/register feature until a patch is available. Restrict access to this feature to minimize the risk of exploitation. Avoid using the vulnerable feature in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02379
CVE-2021-44629

Affected Products

Tp-Link Wr-886N