CVE-2022-26987

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7660_firmware:2.0.30:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7660:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7661_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7661:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7620:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr5660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr5660:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mercusys:mercury_d196g_firmware:20200109_2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:mercusys:mercury_d196g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:fastcom:fac1900r_firmware:20190827_2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:fastcom:fac1900r:-:*:*:*:*:*:*:*

History

21 Nov 2024, 06:54

Type Values Removed Values Added
References () http://tp-link.com - Vendor Advisory () http://tp-link.com - Vendor Advisory
References () https://drive.google.com/file/d/1SnNoqRlJiBD673UROLwdgg_roMOneVR9/view?usp=sharing - Exploit, Third Party Advisory () https://drive.google.com/file/d/1SnNoqRlJiBD673UROLwdgg_roMOneVR9/view?usp=sharing - Exploit, Third Party Advisory
References () https://github.com/GANGE666 - Third Party Advisory () https://github.com/GANGE666 - Third Party Advisory

Information

Published : 2022-05-10 15:15

Updated : 2024-11-21 06:54


NVD link : CVE-2022-26987

Mitre link : CVE-2022-26987

CVE.ORG link : CVE-2022-26987


JSON object : View

Products Affected

tp-link

  • tl-wdr7661
  • tl-wdr5660
  • tl-wdr7660_firmware
  • tl-wdr7620_firmware
  • tl-wdr7661_firmware
  • tl-wdr5660_firmware
  • tl-wdr7620
  • tl-wdr7660

fastcom

  • fac1900r
  • fac1900r_firmware

mercusys

  • mercury_d196g_firmware
  • mercury_d196g
CWE
CWE-787

Out-of-bounds Write