PT-2022-6285 · Tp Link · Tp-Link Wr710N+1
Jonathan Bar
·
Published
2022-12-14
·
Updated
2024-12-20
·
CVE-2022-4498
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link Archer C5 version 2
TP-Link WR710N version 1
Description
The issue is related to a heap-based buffer overflow when handling packets, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The
httpd service is vulnerable when receiving HTTP Basic Authentication, allowing a crafted packet to cause a heap overflow. This can result in either a denial of service by crashing the httpd process or arbitrary code execution.Recommendations
For TP-Link Archer C5 version 2, consider disabling the
httpd service until a patch is available to prevent exploitation.
For TP-Link WR710N version 1, restrict access to the httpd service to minimize the risk of exploitation.Fix
Memory Corruption
Buffer Overflow
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tp-Link Archer C5
Tp-Link Wr710N