Vulnerability Description
TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wa850Re Firmware | < v6_200923 |
| Tp-Link | Tl-Wa850Re | 6 |
Related Weaknesses (CWE)
References
- https://github.com/emremulazimoglu/cve/blob/main/CWE330-TL-WA850RE-v6.mdExploitIssue TrackingThird Party Advisory
- https://www.tp-link.com/us/support/download/tl-wa850re/v6/#FirmwareProductVendor Advisory
- https://github.com/emremulazimoglu/cve/blob/main/CWE330-TL-WA850RE-v6.mdExploitIssue TrackingThird Party Advisory
- https://www.tp-link.com/us/support/download/tl-wa850re/v6/#FirmwareProductVendor Advisory
FAQ
What is CVE-2022-22922?
CVE-2022-22922 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TP-Link TL-WA850RE Wi-Fi Range Extender before v6_200923 was discovered to use highly predictable and easily detectable session keys, allowing attackers to gain administrative privileges.
How severe is CVE-2022-22922?
CVE-2022-22922 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-22922?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wa850Re Firmware, Tp-Link Tl-Wa850Re.