PT-2024-5749 · Tp Link · Tp-Link Re365
Chen Xiao
+1
·
Published
2024-08-19
·
Updated
2024-10-24
·
CVE-2024-42815
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
TP-Link RE365 version V1 180213
Description
The issue is related to a buffer overflow vulnerability due to the lack of length verification for the
USER AGENT field in /usr/bin/httpd. This vulnerability can be exploited by attackers to cause the remote target device to crash or execute arbitrary commands. The vulnerability is related to the USER AGENT field, which can be exploited by sending specially crafted network packets.Recommendations
As a temporary workaround, consider disabling the
httpd service or restricting access to the /usr/bin/httpd endpoint until a patch is available. Update the firmware to the latest version to secure the network. Restrict access to the vulnerable USER AGENT field to minimize the risk of exploitation.Exploit
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Tp-Link Re365