First published: Tue Dec 20 2022(Updated: )
An issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
TP-Link TL-WRN841N Firmware | <=3.13.9 | |
TP-Link TL-WR841ND Firmware | ||
All of | ||
TP-Link TL-WR841ND V7 | <=3.13.9 | |
TP-Link TL-WR841ND V7 | ||
TP-Link TL-WRN841N Firmware | <=3.13.9 | |
TP-Link TL-WR841ND Firmware | ||
TP-Link TL-WR841ND V7 | <=3.13.9 | |
TP-Link TL-WR841ND V7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-46912 is an issue in the firmware update process of TP-Link TL-WR841N / TL-WA841ND V7 3.13.9 and earlier that allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via uploading a crafted firmware image.
CVE-2022-46912 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware image to TP-Link TL-WR841N / TL-WA841ND V7 devices.
CVE-2022-46912 has a severity rating of 8.8 (high).
To fix CVE-2022-46912, update the firmware of TP-Link TL-WR841N / TL-WA841ND V7 to version 3.13.10 or later.
For more information about CVE-2022-46912, you can refer to the following references: [HackMD](https://hackmd.io/@slASVrz_SrW7NQCsunofeA/Sk6sfbTPi) and [TP-Link Security Advisory](https://www.tp-link.com/us/press/security-advisory/).