CVE-2022-26987

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7660_firmware:2.0.30:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7660:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7661_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7661:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7620:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr5660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr5660:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mercusys:mercury_d196g_firmware:20200109_2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:mercusys:mercury_d196g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:fastcom:fac1900r_firmware:20190827_2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:fastcom:fac1900r:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2022-05-10 15:15

Updated : 2024-02-28 19:09


NVD link : CVE-2022-26987

Mitre link : CVE-2022-26987

CVE.ORG link : CVE-2022-26987


JSON object : View

Products Affected

mercusys

  • mercury_d196g_firmware
  • mercury_d196g

tp-link

  • tl-wdr5660_firmware
  • tl-wdr7620_firmware
  • tl-wdr7620
  • tl-wdr7660_firmware
  • tl-wdr7661
  • tl-wdr5660
  • tl-wdr7661_firmware
  • tl-wdr7660

fastcom

  • fac1900r_firmware
  • fac1900r
CWE
CWE-787

Out-of-bounds Write