9.8

CVE-2022-4498

A vulnerable HTTP Basic Authentication process in TP-Link routers, Archer C5 and WR710N-V1, is susceptible to either a DoS or an arbitrary code execution via any interface.

In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Archer C5 Firmware Version 2_160201_us
   Tp-link ≫ Archer C5 Version 2.0
Tp-link ≫ Tl-wr710n Firmware Version 1_151022_us
   Tp-link ≫ Tl-wr710n Version 1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.78% 0.754
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA-ADP 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://kb.cert.org/vuls/id/572615
Third Party Advisory
US Government Resource
VDB Entry
https://www.kb.cert.org/vuls/id/572615