vendor:
VN020-F3v(T) Router
by:
Mohamed Maatallah
6.1
CVSS
HIGH
Denial of Service (DoS)
119
CWE
Product Name: VN020-F3v(T) Router
Affected Version From: TT_V6.2.1021 (VN020-F3v(T))
Affected Version To: TT_V6.2.1021 (VN020-F3v(T))
Patch Exists: NO
Related CWE: CVE-2024-12342
CPE: h:tp-link:vn020-f3v:tt_v6.2.1021
Platforms Tested: VN020-F3v(T) Router (Hardware Version 1.0)
2024
TP-Link VN020 F3v(T) TT_V6.2.1021 – Denial Of Service (DOS)
Two critical vulnerabilities found in TP-Link VN020-F3v(T) router's UPnP implementation affecting the WANIPConnection service. These vulnerabilities enable unauthenticated attackers to trigger denial of service and potential memory corruption via malformed SOAP requests.
Mitigation:
To mitigate these vulnerabilities, users are advised to disable UPnP on the affected router or restrict access to the WANIPConnection service.