PT-2024-31966 · Tp Link · Tp-Link Tl-Wr845N

Published

2024-12-10

·

Updated

2025-06-20

·

CVE-2024-46341

CVSS v3.1

8.0

High

VectorAV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link TL-WR845N(UN) version V4 190219
Description The issue concerns the transmission of credentials in base64 encoded form, which can be easily decoded by an attacker executing a man-in-the-middle attack. This allows the attacker to obtain sensitive information.
Recommendations For TP-Link TL-WR845N(UN) version V4 190219, consider disabling the feature that transmits credentials in base64 encoded form until a patch is available. Restrict access to the device to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Insufficiently Protected Credentials

Weakness Enumeration

Related Identifiers

CVE-2024-46341

Affected Products

Tp-Link Tl-Wr845N