CVE-2022-26987

TP-Link TL-WDR7660 2.0.30, Mercury D196G 20200109_2.0.4, and Fast FAC1900R 20190827_2.0.2 routers have a stack overflow issue in `MmtAtePrase` function. Local users could get remote code execution.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7660_firmware:2.0.30:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7660:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7661_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7661:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr7620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7620:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:tp-link:tl-wdr5660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr5660:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mercusys:mercury_d196g_firmware:20200109_2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:mercusys:mercury_d196g:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:fastcom:fac1900r_firmware:20190827_2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:fastcom:fac1900r:-:*:*:*:*:*:*:*

History

16 May 2022, 16:51

Type Values Removed Values Added
CPE cpe:2.3:o:tp-link:tl-wdr7660_firmware:2.0.30:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr7620_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:fastcom:fac1900r_firmware:20190827_2.0.2:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7660:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr7661_firmware:-:*:*:*:*:*:*:*
cpe:2.3:o:tp-link:tl-wdr5660_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr5660:-:*:*:*:*:*:*:*
cpe:2.3:h:fastcom:fac1900r:-:*:*:*:*:*:*:*
cpe:2.3:o:mercusys:mercury_d196g_firmware:20200109_2.0.4:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7661:-:*:*:*:*:*:*:*
cpe:2.3:h:tp-link:tl-wdr7620:-:*:*:*:*:*:*:*
cpe:2.3:h:mercusys:mercury_d196g:-:*:*:*:*:*:*:*
CWE CWE-787
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
First Time Tp-link
Mercusys mercury D196g Firmware
Tp-link tl-wdr7660 Firmware
Fastcom fac1900r
Mercusys mercury D196g
Tp-link tl-wdr7620 Firmware
Fastcom
Tp-link tl-wdr7661
Tp-link tl-wdr7661 Firmware
Tp-link tl-wdr5660 Firmware
Tp-link tl-wdr7660
Tp-link tl-wdr5660
Fastcom fac1900r Firmware
Mercusys
Tp-link tl-wdr7620
References (MISC) http://tp-link.com - (MISC) http://tp-link.com - Vendor Advisory
References (MISC) https://drive.google.com/file/d/1SnNoqRlJiBD673UROLwdgg_roMOneVR9/view?usp=sharing - (MISC) https://drive.google.com/file/d/1SnNoqRlJiBD673UROLwdgg_roMOneVR9/view?usp=sharing - Exploit, Third Party Advisory
References (MISC) https://github.com/GANGE666 - (MISC) https://github.com/GANGE666 - Third Party Advisory

10 May 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-10 15:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-26987

Mitre link : CVE-2022-26987

CVE.ORG link : CVE-2022-26987


JSON object : View

Products Affected

tp-link

  • tl-wdr7661
  • tl-wdr7661_firmware
  • tl-wdr7660
  • tl-wdr5660
  • tl-wdr5660_firmware
  • tl-wdr7620
  • tl-wdr7660_firmware
  • tl-wdr7620_firmware

mercusys

  • mercury_d196g
  • mercury_d196g_firmware

fastcom

  • fac1900r_firmware
  • fac1900r
CWE
CWE-787

Out-of-bounds Write