PT-2024-9320 · Tp Link · Tp-Link Vn020 F3V

Mohamed Maatallah

·

Published

2024-12-08

·

Updated

2024-12-10

·

CVE-2024-12344

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: TP-Link VN020 F3v(T) TT V6.2.1021
Description: A critical issue was found in the FTP USER Command Handler component of the TP-Link VN020 F3v(T) router, affecting an unknown part of this component. The manipulation of this issue leads to memory corruption and can be initiated remotely.
Recommendations: For TP-Link VN020 F3v(T) TT V6.2.1021, as a temporary workaround, consider disabling the FTP USER Command Handler until a patch is available. Restrict access to the FTP service to minimize the risk of exploitation. Avoid using the FTP protocol until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Memory Corruption

Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2024-11010
CVE-2024-12344

Affected Products

Tp-Link Vn020 F3V