Entreprise d'experts en Sécurité Informatique : Audits et conseils en cybersécurité
Entreprise française de cybersécurité depuis 2004
☎ 03 60 47 09 81 - info@securiteinfo.com


CVE-2022-46432

Description

An exploitable firmware modification vulnerability was discovered on TP-Link TL-WR743ND V1. An attacker can conduct a MITM (Man-in-the-Middle) attack to modify the user-uploaded firmware image and bypass the CRC check, allowing attackers to execute arbitrary code or cause a Denial of Service (DoS). This affects v3.12.20 and earlier.

POC

Reference

- https://hackmd.io/%40slASVrz_SrW7NQCsunofeA/B1Vgv1uwo

- https://hackmd.io/@slASVrz_SrW7NQCsunofeA/B1Vgv1uwo

Github

No PoCs found on GitHub currently.