TP-Link CVE-2022-30075
by - Thursday, January 1, 1970 at 12:00 AM
CVE-2022-30075
Authenticated Remote Code Execution in Tp-Link Routers
  • Affected Devices

If your Tp-Link router has backup and restore functionality and firmware is older than june 2022, it is probably vulnerable

  • Tested With

Tp-Link Archer AX50, other tplink routers may use different format of backups and exploit needs to be modified

  • PoC

Using exploit for starting telnet daemon on the router
tplink 

  • Timeline

15.03.2022 - Identified vulnerability 
15.03.2022 - Contacted Tp-Link support 
16.03.2022 - Recieved response from Tp-Link 
02.05.2022 - Assigned CVE 
27.05.2022 - Tp-Link released firmware with fixed vulnerability 
07.06.2022 - Published technical details 

  • Download Poc
    Hidden Content
    You must register or login to view this content.
    LINK IS DEAD
Reply
awesome! tnx a lot for sharing
Reply
so good
Reply
nicee
Reply
Thanx
Reply
Thanks
Reply
nice work!
Reply
The TP-Link Update is apply to all devices automatic? or manual mode?
Reply
I will do something
Reply
nice!
Reply


 Users viewing this thread: TP-Link CVE-2022-30075: No users currently viewing.