Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2022-42433: ZDI-22-1466

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N TL-WR841N(US)_V14_220121 routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the ated_tp service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-17356.

CVE
#vulnerability#rce#auth

October 25th, 2022

TP-Link TL-WR841N ated_tp Command Injection Remote Code Execution Vulnerability****ZDI-22-1466
ZDI-CAN-17356

CVE ID

CVE-2022-42433

CVSS SCORE

6.4, (AV:A/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)

AFFECTED VENDORS

TP-Link

AFFECTED PRODUCTS

TL-WR841N

VULNERABILITY DETAILS

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR841N routers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed.

The specific flaw exists within the ated_tp service. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of root.

ADDITIONAL DETAILS

Fixed in firmware 220914.

DISCLOSURE TIMELINE

  • 2022-07-19 - Vulnerability reported to vendor
  • 2022-10-25 - Coordinated public release of advisory

CREDIT

Cyrille Chatras

BACK TO ADVISORIES

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907