CVE-2024-48714: Medium severity tp-link tl-wdr7660 firmware vulnerability
Published Oct 15, 2024
·Updated
In TP-Link TL-WDR7660 v1.0, the guestRuleJsonToBin function handles the parameter string name without checking it, which can lead to stack overflow vulnerabilities.
Affected Software
3 affected components
TP-Link TL-WDR7660
All of the following
TP-Link Tl-wdr7660 Firmware=1.0
TP-Link TL-WDR7660
Event History
Oct 15, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-48714?
CVE-2024-48714 is considered a critical vulnerability due to the potential for remote code execution via stack overflow.
2
How do I fix CVE-2024-48714?
To fix CVE-2024-48714, ensure that you update the firmware of the TP-Link TL-WDR7660 to the latest version provided by the vendor.
3
What devices are affected by CVE-2024-48714?
CVE-2024-48714 affects TP-Link TL-WDR7660 version 1.0 routers.
4
What type of vulnerability is CVE-2024-48714?
CVE-2024-48714 is classified as a stack overflow vulnerability due to improper handling of user input.
5
Can CVE-2024-48714 be exploited remotely?
Yes, CVE-2024-48714 can be exploited remotely if the attacker sends malicious requests to the vulnerable router.