Stack-based Buffer Overflow Remote Code Execution Vulnerability
CVE-2024-1179

8.8HIGH

Key Information:

Vendor

TP-Link

Vendor
CVE Published:
1 April 2024

What is CVE-2024-1179?

The TP-Link Omada ER605 routers are prone to a stack-based buffer overflow vulnerability due to improper handling of DHCPv6 client options. This security flaw allows attackers adjacent to the network to execute arbitrary code on the affected devices without the need for authentication. Exploitation of this vulnerability can lead to significant security breaches, as it enables an attacker to run code in the context of the root user, potentially compromising the integrity of the entire network.

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.