First published: Tue Dec 20 2022(Updated: )
An issue in the firmware update process of TP-Link TL-WR941ND V2/V3 up to 3.13.9 and TL-WR941ND V4 up to 3.12.8 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
TP-Link TL-WR941ND Firmware | <=3.13.9 | |
TP-Link TL-WR941ND V2 Firmware | ||
TP-Link TL-WR941ND Firmware | <=3.13.9 | |
TP-Link TL-WR941ND V3 Firmware | ||
TP-Link TL-WR941ND Firmware | <=3.12.8 | |
TP-Link TL-WR941ND V4 Firmware | ||
All of | ||
TP-Link TL-WR941ND Firmware | <=3.13.9 | |
TP-Link TL-WR941ND V2 Firmware | ||
All of | ||
TP-Link TL-WR941ND Firmware | <=3.13.9 | |
TP-Link TL-WR941ND V3 Firmware | ||
All of | ||
TP-Link TL-WR941ND Firmware | <=3.12.8 | |
TP-Link TL-WR941ND V4 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46435 has a high severity due to its potential to allow attackers to execute arbitrary code or cause a Denial of Service.
To fix CVE-2022-46435, update the firmware of TP-Link TL-WR941ND to versions higher than 3.13.9 for V2 and V3, or higher than 3.12.8 for V4.
CVE-2022-46435 affects TP-Link TL-WR941ND V2, V3 up to firmware version 3.13.9, and V4 up to firmware version 3.12.8.
Yes, CVE-2022-46435 can cause a Denial of Service if exploited through the vulnerable firmware update process.
CVE-2022-46435 can be exploited to execute arbitrary code or perform Denial of Service attacks on affected devices.