TP-Link device TL-WDR7660 2.0.30 and TL-WR886N 2.0.12 has a stack overflow vulnerability via the function upgradeInfoJsonToBin.
The product writes data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://github.com/Archerber/bug_submit/blob/main/TP-Link/TL-WDR7660/2.md | third party advisory exploit |
https://github.com/Jianchun-Ding/CVE-poc-update |