Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence

Subscribe to Updates

Get the latest National Security News directly to your inbox.

What's Hot

Spionajul, trădarea de patrie și separatismul vor fi sancționate penal

February 3, 2023

Moment Nish Kumar calls out Dominic Raab on TV after deputy prime minister mistook him for ‘another brown guy’

February 3, 2023

China spy balloon is a ‘threat’ to American sovereignty and ‘not just an isolated incident,’ Gallagher says

February 3, 2023
Facebook Twitter Instagram
  • Privacy Policy
  • Terms and Conditions
  • Contact
Friday, February 3
Estonian Free PressEstonian Free Press
  • National Security
    • United States
    • United Kingdom
    • Europe
    • Estonia
    • Latvia
    • Lithuania
    • Moldova
    • Poland
    • Russia
    • Ukraine
  • Counterterrorism
  • Cybersecurity
  • Intelligence
en English
en Englishet Estonianlv Latvianlt Lithuanianpl Polishro Romanianru Russianuk Ukrainian
Trending
  • Spionajul, trădarea de patrie și separatismul vor fi sancționate penal
  • Moment Nish Kumar calls out Dominic Raab on TV after deputy prime minister mistook him for ‘another brown guy’
  • China spy balloon is a ‘threat’ to American sovereignty and ‘not just an isolated incident,’ Gallagher says
  • PAS a format scut viu în fața Nataliei Gavrilița: Tauber i-a adus cătușe
  • Lavrov: Moldova nu vrea negocieri pe Transnistria. Reacția Chișinăului
  • Is the US over-militarizing its China strategy?
  • Boris Johnson reveals what he’s been doing with newfound freedom since leaving No 10
  • Russian War Report: Satellite imagery indicates a build-up of air defense missile systems in southern Russia
Subscribe
Facebook Twitter Instagram
Estonian Free PressEstonian Free Press
Home » Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2

Vulnerabilities in TP-Link routers, WR710N-V1-151022 and Archer C5 V2

January 24, 20231 Min Read Cybersecurity
Share
Facebook Twitter LinkedIn Pinterest Email

TP-Link router WR710N-V1-151022 running firmware published 2015-10-22 and Archer-C5-V2-160201 running firmware published 2016-02-01 are susceptible to two vulnerabilities:

  1. A buffer overflow during HTTP Basic Authentication allowing a remote attacker to corrupt memory allocated on a heap causing denial of service or arbitrary code execution;
  2. A side-channel attack via a strcmp() function in the HTTP daemon allowing deterministic guessing of each byte of a username and password input during authentication.

Description

TP-Link device WR710N-V1-151022 is a 150Mbps Wireless N Mini Pocket router, and Archer-C5-V2-160201 is a Wireless Dual Band Gigabit router. These SOHO devices are sold by TP-Link and their latest firmware available as of January 11, 2023, have two vulnerabilities.

CVE-2022-4498 When receiving user input during HTTP Basic Authentication mode, a crafted packet may cause a heap overflow in the httpd daemon. This can lead to denial of service (DoS) if the httpd process crashes or arbitrary remote code execution (RCE).

CVE-2022-4499 A strcmp() function in httpd, is susceptible to a side-channel attack when used to verify usename and password credentials. By measuring the response time of the vulnerable process, each byte of the username and password strings may be easier to guess.

Read more at the CERT Coordination Center

Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email

Articles Liés

DHS Expands Abraham Accords to Cybersecurity

February 2, 2023 Cybersecurity

EU Council moves to adjust product lifecycle, reporting in new cybersecurity law

January 31, 2023 Cybersecurity

EU countries seek way out of impasse on sovereignty requirements for cloud services

January 30, 2023 Cybersecurity

Joint Cyber Defense Collaborative Announces 2023 Planning Agenda

January 27, 2023 Cybersecurity

CISA, NSA, and MS-ISAC Release Advisory on the Malicious Use of RMM Software

January 27, 2023 Cybersecurity

Mayorkas and European Union Commissioner for Internal Market Breton Meet on Cyber Resilience Cooperation

January 27, 2023 Cybersecurity
Don't Miss
United Kingdom

Moment Nish Kumar calls out Dominic Raab on TV after deputy prime minister mistook him for ‘another brown guy’

By woe whFebruary 3, 20230

Sign up to the Inside Politics email for your free daily briefing on the biggest…

China spy balloon is a ‘threat’ to American sovereignty and ‘not just an isolated incident,’ Gallagher says

February 3, 2023

PAS a format scut viu în fața Nataliei Gavrilița: Tauber i-a adus cătușe

February 3, 2023

Lavrov: Moldova nu vrea negocieri pe Transnistria. Reacția Chișinăului

February 3, 2023
Stay In Touch
  • Facebook
  • Twitter
  • Pinterest
  • Instagram
  • YouTube
  • Vimeo
Our Picks

Boris Johnson reveals what he’s been doing with newfound freedom since leaving No 10

February 3, 2023

Russian War Report: Satellite imagery indicates a build-up of air defense missile systems in southern Russia

February 3, 2023

Scandalul Apă-Canal. Consilier: Noi devenim ostaticii acestui război

February 3, 2023

Official investigation into Dominic Raab could look at allegations he ‘bullied’ anti-Brexit activist

February 3, 2023

Subscribe to Updates

Get the latest National Security News directly to your inbox.

© 2023 Estonian Free Press. All rights reserved.
  • Privacy Policy
  • Terms and Conditions
  • Contact

Type above and press Enter to search. Press Esc to cancel.