PT-2024-9297 · Tp Link · Tp-Link Vn020 F3V

Mohamed Maatallah

+1

·

Published

2024-12-08

·

Updated

2025-05-29

·

CVE-2024-12342

CVSS v4.0

7.1

High

VectorAV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: TP-Link VN020 F3v(T) version TT V6.2.1021
Description: A critical issue affects the Incomplete SOAP Request Handler component, specifically the processing of the file /control/WANIPConnection. This can lead to denial of service when exploited. The attack can only be initiated within the local network. The issue is related to incorrect resource cleanup or release.
Recommendations: For TP-Link VN020 F3v(T) version TT V6.2.1021, as a temporary workaround, consider restricting access to the /control/WANIPConnection file until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

BDU:2024-10985
CVE-2024-12342

Affected Products

Tp-Link Vn020 F3V