CVE-2022-48194: Malicious File Upload
Published Dec 30, 2022
·Updated
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.
Affected Software
4 affected components
TP-Link TL-WR902AC firmware<=3.0.9.1
TP-Link TL-WR902AC=3.0
All of the following
TP-Link TL-WR902AC firmware<=3.0.9.1
TP-Link TL-WR902AC=3.0
Event History
Dec 30, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this TP-Link TL-WR902AC vulnerability?
The vulnerability ID for this TP-Link TL-WR902AC vulnerability is CVE-2022-48194.
2
What is the severity of CVE-2022-48194?
The severity of CVE-2022-48194 is high with a CVSS score of 8.8.
3
How can remote authenticated attackers exploit CVE-2022-48194?
Remote authenticated attackers can exploit CVE-2022-48194 by uploading a crafted firmware update.
4
What can remote authenticated attackers achieve by exploiting CVE-2022-48194?
Remote authenticated attackers can execute arbitrary code or cause a Denial of Service (DoS) by exploiting CVE-2022-48194.
5
How can I mitigate the CVE-2022-48194 vulnerability?
To mitigate the CVE-2022-48194 vulnerability, apply the latest firmware update provided by TP-Link.