PT-2022-6285 · Tp Link · Tp-Link Wr710N+1

Jonathan Bar

·

Published

2022-12-14

·

Updated

2024-12-20

·

CVE-2022-4498

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Archer C5 version 2 TP-Link WR710N version 1
Description The issue is related to a heap-based buffer overflow when handling packets, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The httpd service is vulnerable when receiving HTTP Basic Authentication, allowing a crafted packet to cause a heap overflow. This can result in either a denial of service by crashing the httpd process or arbitrary code execution.
Recommendations For TP-Link Archer C5 version 2, consider disabling the httpd service until a patch is available to prevent exploitation. For TP-Link WR710N version 1, restrict access to the httpd service to minimize the risk of exploitation.

Fix

Memory Corruption

Buffer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2023-00742
CVE-2022-4498

Affected Products

Tp-Link Archer C5
Tp-Link Wr710N