Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-12343


A vulnerability classified as critical has been found in TP-Link VN020 F3v(T) TT_V6.2.1021. Affected is an unknown function of the file /control/WANIPConnection of the component SOAP Request Handler. The manipulation of the argument NewConnectionType leads to buffer overflow. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used.


Published

2024-12-08T10:15:04.637

Last Modified

2024-12-10T23:26:52.047

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 6.5 (MEDIUM)

CVSSv2 Vector

AV:A/AC:L/Au:N/C:N/I:N/A:C

  • Access Vector: ADJACENT_NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: COMPLETE
Exploitability Score

6.5

Impact Score

6.9

Weaknesses
  • Type: Primary
    CWE-119
    CWE-120

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System tp-link vn020_f3v_firmware 6.2.1021 Yes
Hardware tp-link vn020_f3v - No

References