Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-48194


TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.


Published

2022-12-30T07:15:07.963

Last Modified

2025-04-10T19:15:50.080

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Primary
    CWE-434
  • Type: Secondary
    CWE-434

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link tl-wr902ac_firmware ≤ 3.0.9.1 Yes
Hardware tp-link tl-wr902ac 3.0 No

References