TP-Link Vulnerabilities and Affected Products
Vulnerabilities associated with AC1750.
Products
Clear product- tl-wr886n_firmware14 vulnerabilities
- AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3)12 vulnerabilities
- ac1350_firmware11 vulnerabilities
- N300 Wireless Access Point (EAP115)10 vulnerabilities
- n300_firmware10 vulnerabilities
- Archer A79 vulnerabilities
- ER7206 Omada Gigabit VPN Router9 vulnerabilities
- TL-WR841N8 vulnerabilities
- TL-WR940N8 vulnerabilities
- Omada ER6057 vulnerabilities
- tl-wdr7660_firmware6 vulnerabilities
- tl-wr941nd5 vulnerabilities
- AC17504 vulnerabilities
- Archer AX30004 vulnerabilities
- Archer AX54004 vulnerabilities
- tl-wr840n_firmware4 vulnerabilities
- VN020 F3v(T)4 vulnerabilities
- Archer Air R53 vulnerabilities
- Archer AX213 vulnerabilities
- Archer AXE753 vulnerabilities
- Archer C53 vulnerabilities
- Archer C503 vulnerabilities
- TL-WR902AC3 vulnerabilities
- tl-wr902ac_firmware3 vulnerabilities
- TP-Link TL-WRN841N3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2022-24352HIGH | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 211210 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko kernel module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was Z… CWE-125Mar 28, 2023 | CVSS8.8v3.1 | EPSS0.739% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-24353HIGH | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko module. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context … CWE-125Mar 28, 2023 | CVSS8.8v3.1 | EPSS0.739% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2022-24354HIGH | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link AC1750 prior to 1.1.4 Build 20211022 rel.59103(5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the NetUSB.ko module. The issue results from the lack of proper validation of user-supplied data, which can result in an integer overflow before allocating a buffer. An attacker can leverage this vulnerability to execute code in… CWE-190Feb 18, 2022 | CVSS8.8v3.1 | EPSS1.79% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27246HIGH | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Archer A7 AC1750 1.0.15 routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of MAC addresses by the tdpServer endpoint. A crafted TCP message can write stack pointers to the stack. An attacker can leverage this vulnerability to execute code in the context of the root user. Was ZDI-CAN-12306. CWE-121Apr 14, 2021 | CVSS8.0v3.1 | EPSS6.6% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |