CVE-2023-48724

HIGH

TP-Link EAP225 V3 v5.1.0 Build 20220926 - Unauthenticated Denial of Service via Crafted HTTP POST Request

Title source: llm
STIX 2.1

Description

A memory corruption vulnerability exists in the web interface functionality of Tp-Link AC1350 Wireless MU-MIMO Gigabit Access Point (EAP225 V3) v5.1.0 Build 20220926. A specially crafted HTTP POST request can lead to denial of service of the device's web interface. An attacker can send an unauthenticated HTTP POST request to trigger this vulnerability.

References (2)

Core 2

Scores

CVSS v3 7.5
EPSS 0.0043
EPSS Percentile 62.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-121 CWE-787
Status published
Products (1)
tp-link/eap225_firmware 5.1.0
Published Apr 09, 2024
Tracked Since Feb 18, 2026