Heap-based Buffer Overflow Remote Code Execution Vulnerability Affects TP-Link Omada ER605 Routers
CVE-2024-5228
7.5HIGH
What is CVE-2024-5228?
A newly discovered buffer overflow vulnerability in TP-Link's Omada ER605 routers, specifically during the handling of DNS responses, could allow remote attackers to execute arbitrary code. This issue stems from inadequate validation of user-supplied data length before it is copied to a fixed-length heap-based buffer. The vulnerability is particularly concerning for those using the Comexe DDNS service, as no authentication is needed to exploit it. Protect your devices by avoiding this configuration or applying necessary updates.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published