First published: Tue Dec 20 2022(Updated: )
An issue in the firmware update process of TP-Link TL-WA901ND V1 up to v3.11.2 and TL-WA901N V2 up to v3.12.16 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
TP-Link TL-WA901N | <=3.11.2 | |
TP-Link TL-WA901N Firmware | ||
All of | ||
TP-Link TL-WA901ND Firmware | <=3.11.2 | |
TP-Link TL-WA901N | ||
All of | ||
TP-Link TL-WA901N | >=3.12.0<=3.12.16 | |
TP-Link TL-WA901N Firmware | ||
All of | ||
TP-Link TL-WA901ND V2 | <=3.12.16 | |
TP-Link TL-WA901ND V2 Firmware | ||
TP-Link TL-WA901N | <=3.11.2 | |
TP-Link TL-WA901N Firmware | ||
TP-Link TL-WA901ND Firmware | <=3.11.2 | |
TP-Link TL-WA901N | ||
TP-Link TL-WA901N | >=3.12.0<=3.12.16 | |
TP-Link TL-WA901ND V2 | <=3.12.16 | |
TP-Link TL-WA901ND V2 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46910 has a high severity rating due to its potential to allow arbitrary code execution and Denial of Service (DoS).
To mitigate CVE-2022-46910, update the TP-Link TL-WA901ND V1 or TL-WA901N V2 to the latest firmware versions beyond 3.11.2 and 3.12.16 respectively.
CVE-2022-46910 affects TP-Link TL-WA901ND V1 up to firmware version 3.11.2 and TL-WA901N V2 up to firmware version 3.12.16.
Yes, CVE-2022-46910 can be exploited remotely by uploading a crafted firmware image.
The exploitation of CVE-2022-46910 can lead to arbitrary code execution on affected devices or cause a Denial of Service (DoS).