Vulnerability Description
TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Tp-Link | Tl-Wr886N Firmware | 3.0.14 |
| Tp-Link | Tl-Wr886N | 7.0 |
Related Weaknesses (CWE)
References
- https://github.com/Jianchun-Ding/CVE-POC-update2/tree/main
- https://github.com/XYIYM/Digging/blob/main/TP-LINK/TL-WR886N/2/1.mdExploitThird Party Advisory
- https://resource.tp-link.com.cn/pc/docCenter/showDoc?id=1676623713687165Product
- https://github.com/XYIYM/Digging/blob/main/TP-LINK/TL-WR886N/2/1.mdExploitThird Party Advisory
- https://resource.tp-link.com.cn/pc/docCenter/showDoc?id=1676623713687165Product
FAQ
What is CVE-2023-46522?
CVE-2023-46522 is a vulnerability with a CVSS score of 9.8 (CRITICAL). TP-LINK device TL-WR886N V7.0_3.0.14_Build_221115_Rel.56908n.bin and TL-WDR7660 2.0.30 were discovered to contain a stack overflow via the function deviceInfoRegister.
How severe is CVE-2023-46522?
CVE-2023-46522 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-46522?
Check the references section above for vendor advisories and patch information. Affected products include: Tp-Link Tl-Wr886N Firmware, Tp-Link Tl-Wr886N.