github.comexploit
https://github.com/Zephkek/TP-1450 CVE-2024-12344
MEDIUM
TP-Link VN020 F3v(T) FTP USER Command memory corruption
Record summary
CVE-2024-12344 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Dec 9, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
VN020 F3v(T)Browse TP-Link / VN020 F3v(T) | CVE List | TT_V6.2.1021 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBTP-Link VN020 F3v(T) TT_V6.2.1021 - Buffer Overflow Memory CorruptionExploitDB exploitby Mohamed MaatallahNot analyzed1 file
References
6nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-12344 VDB-287265 | CTI Indicators (IOB, IOC)signaturepermissions required
https://vuldb.com/?ctiid.287265 VDB-287265 | TP-Link VN020 F3v(T) FTP USER Command memory corruptionvdb entry
https://vuldb.com/?id.287265 Submit #452658 | TP-Link VN020 F3v(T) Hardware Version: 1.0 / Firmware Version: TT_V6.2.1021 Buffer Overflow & Memory corruptionThird-party advisory
https://vuldb.com/?submit.452658 tp-link.comproduct
https://www.tp-link.com/