CVE-2024-48714
CVE-2024-48714 is a stack overflow vulnerability in TP-Link TL-WDR7660 v1.0 routers. The guestRuleJsonToBin
function improperly handles the string name
parameter, creating a potential attack vector. This vulnerability allows attackers to potentially execute arbitrary code by exploiting the unchecked string input.
While CVE-2024-48714 has a CVSS score of 0, indicating a low base severity, the SOCRadar Vulnerability Risk Score (SVRS) is 30. This suggests some level of real-world exploitability, especially since the vulnerability is tagged as "In The Wild". Even with the relatively low SVRS score immediate action is advised, as it indicates there is at least some active exploitation or proof-of-concept code circulating. The risk includes potential compromise of affected TP-Link routers, leading to network disruption and unauthorized access. Businesses and individuals using this router model should investigate further and apply any available patches or mitigations.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.