CVE-2021-29302

TP-Link TL-WR802N(US), Archer_C50v5_US v4_200 <= 2020.06 contains a buffer overflow vulnerability in the httpd process in the body message. The attack vector is: The attacker can get shell of the router by sending a message through the network, which may lead to remote code execution.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wr802n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr802n:v4:*:*:*:*:*:*:*

History

07 Nov 2023, 03:32

Type Values Removed Values Added
References
  • {'url': 'https://static.tp-link.com/beta/2021/202103/20210319/TL-WR802Nv4_US_0.9.1_3.17_up_boot[210317-rel64474].zip', 'name': 'https://static.tp-link.com/beta/2021/202103/20210319/TL-WR802Nv4_US_0.9.1_3.17_up_boot[210317-rel64474].zip', 'tags': ['Vendor Advisory'], 'refsource': 'MISC'}
  • () https://static.tp-link.com/beta/2021/202103/20210319/TL-WR802Nv4_US_0.9.1_3.17_up_boot%5B210317-rel64474%5D.zip -

21 Apr 2021, 16:42

Type Values Removed Values Added
References (MISC) https://static.tp-link.com/beta/2021/202103/20210319/TL-WR802Nv4_US_0.9.1_3.17_up_boot[210317-rel64474].zip - Broken Link (MISC) https://static.tp-link.com/beta/2021/202103/20210319/TL-WR802Nv4_US_0.9.1_3.17_up_boot[210317-rel64474].zip - Vendor Advisory
References (MISC) https://www.tp-link.com/us/support/download/tl-wr802n/#Firmware - (MISC) https://www.tp-link.com/us/support/download/tl-wr802n/#Firmware - Vendor Advisory
References (MISC) https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-29302 - (MISC) https://github.com/liyansong2018/CVE/tree/main/2021/CVE-2021-29302 - Exploit, Third Party Advisory
CWE CWE-120
CPE cpe:2.3:o:tp-link:tl-wr802n_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wr802n:v4:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 9.3
v3 : 8.1

12 Apr 2021, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-04-12 19:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-29302

Mitre link : CVE-2021-29302

CVE.ORG link : CVE-2021-29302


JSON object : View

Products Affected

tp-link

  • tl-wr802n
  • tl-wr802n_firmware
CWE
CWE-120

Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')