packetstormsecurity.com
http://packetstormsecurity.com/files/171623/TP-Link-TL-WR902AC-Remote-Code-Execution.html CVE-2022-48194
HIGH
TP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)
Record summary
CVE-2022-48194 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit and 1 repository PoC.
Description
TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.
Description source: CVE List
Exploitation context
Proofs of concept
2Catalogued exploits
ExploitDBTP-Link TL-WR902AC firmware 210730 (V3) - Remote Code Execution (RCE) (Authenticated)ExploitDB exploitby Tobias MüllerNot analyzed1 file
Repository PoCs
GitHubotsmr/internet-of-vulnerable-thingsRepository PoCby otsmrStars: 19Not analyzed7 files
References
3github.com
https://github.com/otsmr/internet-of-vulnerable-things/tree/main/exploits nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2022-48194