PT-2023-9013 · Tp Link · Eap225 V3
The Vulnerability
·
Published
2023-12-11
·
Updated
2025-08-21
·
CVE-2023-48724
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) version 5.1.0 Build 20220926
Description
A memory corruption vulnerability exists in the web interface functionality, allowing an attacker to send an unauthenticated HTTP POST request to trigger this issue, leading to denial of service of the device's web interface. The vulnerability can be exploited by sending a specially crafted HTTP POST request.
Recommendations
For Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) version 5.1.0 Build 20220926, as a temporary workaround, consider restricting access to the web interface until a patch is available. Avoid using the web interface functionality until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Stack Overflow
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Eap225 V3