CVE-2020-28877

Buffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620, WDR8640, WDR8660, WR880N, WR886N, WR890N, WR890N, WR882N, and WR708N.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:wdr7400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr7400:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:wdr7500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr7500:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:wdr7660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr7660:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:wdr7800_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr7800:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:tp-link:wdr8400_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8400:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:tp-link:wdr8500_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8500:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:tp-link:wdr8600_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8600:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:tp-link:wdr8620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8620:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:tp-link:wdr8640_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8640:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:tp-link:wdr8660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wdr8660:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:tp-link:wr880n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr880n:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:tp-link:wr886n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr886n:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:tp-link:wr890n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr890n:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:tp-link:wr890n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr890n:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:tp-link:wr882n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr882n:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:tp-link:wr708n_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:wr708n:-:*:*:*:*:*:*:*

History

21 Nov 2024, 05:23

Type Values Removed Values Added
References () https://github.com/peanuts62/TP-Link-pocĀ - Broken Link () https://github.com/peanuts62/TP-Link-pocĀ - Broken Link

Information

Published : 2020-11-20 16:15

Updated : 2024-11-21 05:23


NVD link : CVE-2020-28877

Mitre link : CVE-2020-28877

CVE.ORG link : CVE-2020-28877


JSON object : View

Products Affected

tp-link

  • wdr8660_firmware
  • wr882n_firmware
  • wdr8600_firmware
  • wdr7500
  • wr886n
  • wr880n
  • wdr7660_firmware
  • wdr7800
  • wdr8500_firmware
  • wr890n_firmware
  • wdr8600
  • wdr8660
  • wdr7800_firmware
  • wdr7660
  • wdr7500_firmware
  • wr882n
  • wdr8620
  • wr890n
  • wdr8400
  • wdr8640_firmware
  • wdr8640
  • wr886n_firmware
  • wr708n
  • wdr8620_firmware
  • wr880n_firmware
  • wdr8500
  • wr708n_firmware
  • wdr7400_firmware
  • wdr8400_firmware
  • wdr7400
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')