github.comrelated
https://github.com/Zephkek/TP-Thumper CVE-2024-11237
HIGH
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
Record summary
CVE-2024-11237 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
VN020 F3v(T)Browse TP-Link / VN020 F3v(T) | CVE List | TT_V6.2.1021 | affected |
vn020_f3v_firmwareBrowse tp-link / vn020_f3v_firmwareDefault status: unknown | CVE List | tt_v6.2.1021 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBTP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer OverflowExploitDB exploitby Mohamed MaatallahNot analyzed1 file
References
7github.comexploit
https://github.com/Zephkek/TP-Thumper/blob/main/poc.c nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-11237 VDB-284672 | CTI Indicators (IOB, IOC, IOA)signaturepermissions required
https://vuldb.com/?ctiid.284672 VDB-284672 | TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflowvdb entryTechnical description
https://vuldb.com/?id.284672 Submit #438408 | TP-Link VN020 F3v(T) ISP Routers Hardware Version: 1.0 / Firmware Version: TT_V6.2.1021 Stack-based Buffer OverflowThird-party advisory
https://vuldb.com/?submit.438408 tp-link.comproduct
https://www.tp-link.com/