PT-2022-6285 · Tp Link · Tp-Link Wr710N+1

·

CVE-2022-4498

·

Published

2022-12-14

·

Updated

2024-12-20

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions TP-Link Archer C5 version 2 TP-Link WR710N version 1
Description The issue is related to a heap-based buffer overflow when handling packets, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service. The httpd service is vulnerable when receiving HTTP Basic Authentication, allowing a crafted packet to cause a heap overflow. This can result in either a denial of service by crashing the httpd process or arbitrary code execution.
Recommendations For TP-Link Archer C5 version 2, consider disabling the httpd service until a patch is available to prevent exploitation. For TP-Link WR710N version 1, restrict access to the httpd service to minimize the risk of exploitation.

Fix

Memory Corruption

Buffer Overflow

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-00742
CVE-2022-4498

Affected Products

Tp-Link Archer C5
Tp-Link Wr710N