First published: Tue Dec 20 2022(Updated: )
An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tp-link Tl-wr841n Firmware | <=3.13.9 | |
TP-LINK TL-WR841N | ||
Tp-link Tl-wr841nd V7 Firmware | <=3.13.9 | |
Tp-link Tl-wr841nd V7 | ||
All of | ||
Tp-link Tl-wr841n Firmware | <=3.13.9 | |
TP-LINK TL-WR841N | ||
All of | ||
Tp-link Tl-wr841nd V7 Firmware | <=3.13.9 | |
Tp-link Tl-wr841nd V7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46912 is an issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier that allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
CVE-2022-46912 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware image to TP-Link TL-WR841N / TL-WA841ND V7 devices.
CVE-2022-46912 has a severity rating of 8.8 (high).
To fix CVE-2022-46912, update the firmware of TP-Link TL-WR841N / TL-WA841ND V7 to version 3.13.10 or later.
For more information about CVE-2022-46912, you can refer to the following references: [HackMD](https://hackmd.io/@slASVrz_SrW7NQCsunofeA/Sk6sfbTPi) and [TP-Link Security Advisory](https://www.tp-link.com/us/press/security-advisory/).