Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

TP-Link TL-WR940N: Analysis of a 1day (CVE-2022-24355) Buffer Overflow RCE Vulnerability

blog.viettelcybersecurity.com | vulnerability | CVE-2022-24355 | #rce

Summary

About the bug CVE-2022-24355 allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of file name extensions. The issue results from the lack of proper validation of the length of
Published
Collected

original ↗

Related coverage

back