CVE-2024-25139: Buffer Overflow
In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)v22.2.4 Build 020240119.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-25139?
CVE-2024-25139 has a high severity rating due to the potential for remote code execution.
How do I fix CVE-2024-25139?
To fix CVE-2024-25139, you should update the TP-Link Omada ER605 firmware to a version higher than 2.2.3.
What causes CVE-2024-25139?
CVE-2024-25139 is caused by an integer overflow in the cloud-brd binary that results in a heap-based buffer overflow.
Which versions of TP-Link Omada ER605 are affected by CVE-2024-25139?
TP-Link Omada ER605 version 1.0.1 through 2.2.3 are affected by CVE-2024-25139.
What can an attacker achieve with CVE-2024-25139?
An attacker exploiting CVE-2024-25139 can achieve code execution at the root level within the vulnerable cloud-brd binary.