Record summary

CVE-2024-11237 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.

Description

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 15, 2024 · Source: CVE List

Affected products and versions

2
ProductSourceVersion rangeStatus
CVE ListTT_V6.2.1021affected

Default status: unknown

CVE Listtt_v6.2.1021affected

Proofs of concept

1

Catalogued exploits

ExploitDBTP-Link VN020 F3v(T) TT_V6.2.1021) - DHCP Stack Buffer OverflowExploitDB exploitby Mohamed MaatallahNot analyzed1 file
ExploitDB

PoC details

References

7
VDB-284672 | TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflowvdb entryTechnical description
https://vuldb.com/?id.284672
Submit #438408 | TP-Link VN020 F3v(T) ISP Routers Hardware Version: 1.0 / Firmware Version: TT_V6.2.1021 Stack-based Buffer OverflowThird-party advisory
https://vuldb.com/?submit.438408