Record summary

CVE-2024-12344 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE ListTT_V6.2.1021affected

Proofs of concept

1

Catalogued exploits

ExploitDBTP-Link VN020 F3v(T) TT_V6.2.1021 - Buffer Overflow Memory CorruptionExploitDB exploitby Mohamed MaatallahNot analyzed1 file
ExploitDB

PoC details

References

6
Submit #452658 | TP-Link VN020 F3v(T) Hardware Version: 1.0 / Firmware Version: TT_V6.2.1021 Buffer Overflow & Memory corruptionThird-party advisory
https://vuldb.com/?submit.452658