7.5

CVE-2023-30383

TP-LINK Archer C50v2 Archer C50(US)_V2_160801, TP-LINK Archer C20v1 Archer_C20_V1_150707, and TP-LINK Archer C2v1 Archer_C2_US__V1_170228 were discovered to contain a buffer overflow which may lead to a Denial of Service (DoS) when parsing crafted data.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Tp-link ≫ Archer C2 V1 Firmware Version 170228
   Tp-link ≫ Archer C2 V1 Version -
Tp-link ≫ Archer C20 Firmware Version 150707
   Tp-link ≫ Archer C20 Version 1
Tp-link ≫ Archer C50 Firmware Version 160801
   Tp-link ≫ Archer C50 Version 2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.35% 0.684
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

https://gist.github.com/a2ure123/a4eda2813d85d8b414bb87e855ab4bf8
Third Party Advisory
https://www.tp-link.com/us/support/download/archer-c2/v1/#Firmware
Product
https://www.tp-link.com/us/support/download/archer-c50/v2/#Firmware
Product
https://www.tp-link.com/us/support/download/archer-c50/v2/#Firmware%29%2CTPLINK