Vulnerability Intelligence Report
CVE-2022-25074
TP-Link TL-WR902AC(US)_V3_191209 routers were discovered to contain a stack overflow in the function DM_ Fillobjbystr(). This vulnerability allows unauthenticated attackers to execute arbitrary code.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:13.03%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| tp-link | tl-wr902ac_firmware | 191209 |
| tp-link | tl-wr902ac | 3 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
13.034%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | MITRE Corporation · N/A · USA |
| Reserved | 2022-02-14T00:00:00 |
| Published | 2022-02-22T22:44:06 |
| Last Updated | 2024-08-03T04:29:01 |
Community Chatter & Buzz