CVE-2022-30024: Buffer Overflow
A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)V12160624 and TL-WR841 V11 TL-WR841N(EU)V11160325 , TL-WR841NV11150616 and TL-WR841 V10 TL-WR841NV10150310 are also affected.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict or block unauthenticated access to the Wi‑Fi System Tools page (the endpoint referenced as the System Tools of the Wi‑Fi network) so that a GET request cannot be used by remote attackers.
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-30024.
What devices are affected by this vulnerability?
The TP-Link TL-WR841N V12 devices with firmware version 3.16.9 are affected by this vulnerability.
How does this vulnerability occur?
This vulnerability occurs due to a buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 devices.
What is the severity of CVE-2022-30024?
The severity of CVE-2022-30024 is rated as high with a severity value of 8.8.
How can an attacker exploit this vulnerability?
An authenticated remote attacker can exploit this vulnerability by sending a specially crafted GET request to the System Tools page of the Wi-Fi network.