Record summary

CVE-2022-48194 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.

Description

TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Repository PoCs
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 10, 2025 · Source: CVE List

Proofs of concept

2

Catalogued exploits

ExploitDBTP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Tobias MüllerNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubotsmr/internet-of-vulnerable-thingsRepository PoCby otsmrStars: 19Not analyzed7 files

1.9 MiB

GitHub

PoC details

References

3