CRITICAL🇵🇱 Wersja polska

CVE-2022-25073

CVSS 9.8v3.1pub. 2022-02-24upd. 2024-11-21

TL-WR841Nv14_US_0.9.1_4.18 routers were discovered to contain a stack overflow in the function dm_fillObjByStr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Tp Link Tl Wr841n

    HW
    Tp-Link
    v14
  • Tp Link Tl Wr841n Firmware

    OS
    Tp-Link
    0.9.1_4.18
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEAuth Bypass
CWE
References

Related vulnerabilities

CVE-2018-12575CRITICAL9.8PL ✓same product

TP-Link TL-WR841N — obejście uwierzytelnienia w interfejsie webowym

CVE-2018-11714CRITICAL9.8PL ✓same product

TP-Link TL-WR840N/TL-WR841N — pominięcie uwierzytelnienia poprzez fałszywy nagłówek Referer

CVE-2025-9377HIGH8.6⚠ KEVsame product

The authenticated remote command execution (RCE) vulnerability exists in the Parental Control page on TP-Link...

CVE-2023-33538HIGH8.8⚠ KEVsame product

TP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a command injection v...

CVE-2015-3035HIGH7.5⚠ KEVsame product

Directory traversal vulnerability in TP-LINK Archer C5 (1.2) with firmware before 150317, C7 (2.0) with firmwa...