TP-Link TL-WR902AC devices through V3 0.9.1 allow remote authenticated attackers to execute arbitrary code or cause a Denial of Service (DoS) by uploading a crafted firmware update because the signature check is inadequate.
2022-12-30T07:15:07.963
2025-04-10T19:15:50.080
Modified
CVSSv3.1: 8.8 (HIGH)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Operating System | tp-link | tl-wr902ac_firmware | ≤ 3.0.9.1 | Yes |
Hardware | tp-link | tl-wr902ac | 3.0 | No |