ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Critical Security Vulnerabilities Discovered in Netcomm and TP

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-4498
+1 in the same advisory: …4499
In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted

In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution.

NVD description · AI analysis pending
9.8
group max
2%
  • tp-link archer c5 firmware
  • tp-link tl-wr710n firmware
CVE-2022-4873
+1 in the same advisory: …4874
On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter.

On Netcomm router models NF20MESH, NF20, and NL1902 a stack based buffer overflow affects the sessionKey parameter. By providing a specific number of bytes, the instruction pointer is able to be overwritten on the stack and crashes the application at a known location.

NVD description · AI analysis pending
9.8
group max
7% PoC
  • netcommwireless nf20 firmware
  • netcommwireless nf20mesh firmware
  • netcommwireless nl1902 firmware
Full article269 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 18, 2023Network Security

Security vulnerabilities have been disclosed in Netcomm and TP-Link routers, some of which could be weaponized to achieve remote code execution.

The flaws, tracked as CVE-2022-4873 and CVE-2022-4874, concern a case of stack-based buffer overflow and authentication bypass and impact Netcomm router models NF20MESH, NF20, and NL1902 running firmware versions earlier than R6B035.

"The two vulnerabilities, when chained together, permit a remote, unauthenticated attacker to execute arbitrary code," the CERT Coordination Center (CERT/CC) said in an advisory published Tuesday.

"The attacker can first gain unauthorized access to affected devices, and then use those entry points to gain access to other networks or compromise the availability, integrity, or confidentiality of data being transmitted from the internal network."

Security researcher Brendan Scarvell has been credited with discovering and reporting the issues in October 2022.

In a related development, CERT/CC also detailed two unpatched security vulnerabilities affecting TP-Link routers WR710N-V1-151022 and Archer-C5-V2-160201 that could lead to information disclosure (CVE-2022-4499) and remote code execution (CVE-2022-4498).

CVE-2022-4499 is also a side-channel attack targeting a function used to validate the entered credentials. "By measuring the response time of the vulnerable process, each byte of the username and password strings may be easier to guess," CERT/CC said.

Microsoft researcher James Hull has been acknowledged for disclosing the two bugs. The Hacker News has reached out to TP-Link for a comment, and we will update the story if we hear back.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/01/critical-security-vulnerabilities.html