CVE-2022-26988: High severity TP-Link Tl-wdr7660 Firmware vulnerability
Published May 10, 2022
·Updated
TP-Link TL-WDR7660 2.0.30, Mercury D196G 202001092.0.4, and Fast FAC1900R 201908272.0.2 routers have a stack overflow issue in MntAte function. Local users could get remote code execution.
Affected Software
24 affected components
TP-Link Tl-wdr7660 Firmware=2.0.30
TP-Link TL-WDR7660
TP-Link Tl-wdr7661 Firmware
TP-Link Tl-wdr7661
TP-Link Tl-wdr7620 Firmware
TP-Link Tl-wdr7620
TP-Link Tl-wdr5660 Firmware
TP-Link Tl-wdr5660
MERCUSYS Mercury D196g Firmware=20200109_2.0.4
MERCUSYS Mercury D196g
Fastcom Fac1900r Firmware=20190827_2.0.2
Fastcom Fac1900r
All of the following
TP-Link Tl-wdr7660 Firmware=2.0.30
TP-Link TL-WDR7660
All of the following
TP-Link Tl-wdr7661 Firmware
TP-Link Tl-wdr7661
All of the following
TP-Link Tl-wdr7620 Firmware
TP-Link Tl-wdr7620
All of the following
TP-Link Tl-wdr5660 Firmware
TP-Link Tl-wdr5660
All of the following
MERCUSYS Mercury D196g Firmware=20200109_2.0.4
MERCUSYS Mercury D196g
All of the following
Fastcom Fac1900r Firmware=20190827_2.0.2
Fastcom Fac1900r
Event History
May 10, 2022
CVE Published
via MITRE·02:26 PM
Data Sourced
via MITRE·02:26 PM
Description
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-26988.
2
What is the severity of CVE-2022-26988?
The severity of CVE-2022-26988 is high with a CVSS score of 7.8.
3
Which routers are affected by CVE-2022-26988?
TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers are affected by CVE-2022-26988.
4
What is the impact of CVE-2022-26988?
CVE-2022-26988 allows local users to execute remote code on the affected routers.
5
Are there any fixes available for CVE-2022-26988?
Please refer to the official TP-Link website or the vendor's official support channels for information on available fixes for CVE-2022-26988.