CVE-2024-11237

A vulnerability, which was classified as critical, has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected by this issue is some unknown functionality of the component DHCP DISCOVER Packet Parser. The manipulation of the argument hostname leads to stack-based buffer overflow. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
References
Link Resource
https://github.com/Zephkek/TP-Thumper Exploit Third Party Advisory
https://github.com/Zephkek/TP-Thumper/blob/main/poc.c Exploit
https://vuldb.com/?ctiid.284672 Permissions Required VDB Entry
https://vuldb.com/?id.284672 Third Party Advisory VDB Entry
https://vuldb.com/?submit.438408 Third Party Advisory VDB Entry
https://www.tp-link.com/ Product
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:vn020-f3v\(t\)_firmware:tt_v6.2.1021:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:vn020-f3v\(t\):-:*:*:*:*:*:*:*

History

19 Nov 2024, 19:04

Type Values Removed Values Added
CPE cpe:2.3:o:tp-link:vn020-f3v\(t\)_firmware:tt_v6.2.1021:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:vn020-f3v\(t\):-:*:*:*:*:*:*:*
CWE CWE-787
CVSS v2 : 7.8
v3 : 7.5
v2 : 7.8
v3 : 9.8
References () https://github.com/Zephkek/TP-Thumper - () https://github.com/Zephkek/TP-Thumper - Exploit, Third Party Advisory
References () https://github.com/Zephkek/TP-Thumper/blob/main/poc.c - () https://github.com/Zephkek/TP-Thumper/blob/main/poc.c - Exploit
References () https://vuldb.com/?ctiid.284672 - () https://vuldb.com/?ctiid.284672 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.284672 - () https://vuldb.com/?id.284672 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.438408 - () https://vuldb.com/?submit.438408 - Third Party Advisory, VDB Entry
References () https://www.tp-link.com/ - () https://www.tp-link.com/ - Product
First Time Tp-link vn020-f3v\(t\) Firmware
Tp-link vn020-f3v\(t\)
Tp-link

15 Nov 2024, 13:58

Type Values Removed Values Added
Summary
  • (es) Se ha encontrado una vulnerabilidad clasificada como crítica en TP-Link VN020 F3v(T) TT_V6.2.1021. Este problema afecta a algunas funciones desconocidas del componente DHCP DISCOVER Packet Parser. La manipulación del argumento hostname provoca un desbordamiento del búfer basado en la pila. El ataque puede ejecutarse de forma remota. El exploit se ha hecho público y puede utilizarse.

15 Nov 2024, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-11-15 12:15

Updated : 2024-11-19 19:04


NVD link : CVE-2024-11237

Mitre link : CVE-2024-11237

CVE.ORG link : CVE-2024-11237


JSON object : View

Products Affected

tp-link

  • vn020-f3v\(t\)_firmware
  • vn020-f3v\(t\)
CWE
CWE-787

Out-of-bounds Write

CWE-119

Improper Restriction of Operations within the Bounds of a Memory Buffer

CWE-121

Stack-based Buffer Overflow