HIGH
TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm
Published Aug 21, 2023
7.5
HIGHCVSS 3.1
EPSS 0.74%
Description
TP-Link TL-WR940N V2, TP-Link TL-WR941ND V5 and TP-Link TL-WR841N V8 were discovered to contain a buffer overflow via the component /userRpm/AccessCtrlAccessRulesRpm. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted GET request.
Affected products
No data.
Configuration 1
AND
- n/a
Running on/with
- n/a
Configuration 2
AND
- n/a
Running on/with
- n/a
Configuration 3
AND
- n/a
Running on/with
- n/a
-
- Version 8.0StatusaffectedConstraints-
- Version
-
- Version v5StatusaffectedConstraints-
- Version
-
- Version 2StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| TP-Link | TL-Wr841n | n/a |
| ||||||
| TP-Link | TL-Wr941nd | n/a |
| ||||||
| TP-Link | TL-Wr941nd V2 | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-43445 Advisory
- https://github.com/a101e-IoTvul/iotvul/blob/main/tp-link/16/TP-Link%20WR940N%20WR941ND%20WR841N%20wireless%20router%20userRpmAccessCtrlAccessRulesRpm%20buffer%20read%20out-of-bounds%20vulnerability.md ExploitThird Party Advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Aug 21, 2023
Updated Oct 7, 2024
Reserved Aug 7, 2023
Link CVE-2023-39745
CISA Vulnrichment
Updated Oct 7, 2024
ENISA EUVD
EUVD-2023-43445 Assigner mitre
Published Aug 21, 2023
Updated Oct 7, 2024
Exploited since n/a
Link EUVD-2023-43445