CVE-2024-54887

Published Jan 9, 2025

Last updated a month ago

Overview

Description
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
8
Impact score
5.9
Exploitability score
2.1
Vector string
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

134c704f-9b21-4f2e-91b3-4a467353bcc0
CWE-120

Social media

Hype score
Not currently trending
  1. به تازگی برای یکی از مدل های مودم TP-Link با نام TL-WR940N آسیب پذیری با کد شناسایی CVE-2024-54887 و از نوع RCE منتشر شده است. این آسیب پذیری برای سخت افزارهای ورژن ۳ و ۴ و همچنین جدیدترین به روز رسانی framware این مدل وجود دارد. https://t.co/Poz3aKY03t https://t.co/cLSP82D652

    @AmirHossein_sec

    30 Jan 2025

    21 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. #exploit 1. CVE-2024-54887: TP-Link TL-WR940N BoF - https://t.co/LJfZQYbs0m 2. CVE-2024-41570: Authenticated Havoc-Chained-RCE - https://t.co/jNOBFzBRFX 3. CVE-2025-21298: Windows OLE RCE (CVSS 9.8) - https://t.co/ILiDNHhuf8

    @ksg93rd

    22 Jan 2025

    81 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. A critical vulnerability (CVE-2024-54887) in TP-Link TL-WR940N routers allows arbitrary remote code execution via stack buffer overflow. Affected: hardware versions 3 & 4. ⚠️ #TPLink #RouterVulnerability #USA link: https://t.co/a4LSEqNahE https://t.co/KZTQE5lOOB

    @TweetThreatNews

    22 Jan 2025

    64 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨 Critical alert for TP-Link TL-WR940N routers! A buffer overflow vulnerability (CVE-2024-54887) allows remote code execution. Hardware versions 3 & 4 are impacted. ⚠️ #TPLink #RemoteCodeExec #USA link: https://t.co/INaRIPlLwQ https://t.co/NvkrDDwRxt

    @TweetThreatNews

    21 Jan 2025

    40 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  5. PoC Exploit Released for TP-Link Code Execution Vulnerability(CVE-2024-54887) https://t.co/9AphfwpWyJ

    @Seifreed

    21 Jan 2025

    512 Impressions

    2 Retweets

    12 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  6. TP-Link Zafiyeti: CVE-2024-54887 PoC Exploiti ile Uzaktan Kod Çalıştırma Riskleri https://t.co/B9MEaz4cUF

    @cyberwebeyeos

    21 Jan 2025

    36 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks - https://t.co/iVEcF0D0hV

    @moton

    21 Jan 2025

    73 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨🚨CVE-2024-54887: Critical Vulnerability in TP-Link TL-WR940N Routers ⚠️This flaw is a buffer overflow vulnerability discovered in the device’s handling of IPv6 DNS server configuration parameters, potentially allowing attackers to execute arbitrary code or cause… https://t.co/

    @zoomeye_team

    21 Jan 2025

    55 Impressions

    1 Retweet

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks https://t.co/rb3wmGVJGT

    @Dinosn

    21 Jan 2025

    5770 Impressions

    34 Retweets

    119 Likes

    32 Bookmarks

    7 Replies

    0 Quotes

  10. TP-Link Vulnerability: PoC Exploit for CVE-2024-54887 Reveals Remote Code Execution Risks Critical vulnerability in TP-Link TL-WR940N routers: learn about CVE-2024-54887 and the risk it poses for your network security https://t.co/0NJvdjM1vk

    @the_yellow_fall

    21 Jan 2025

    733 Impressions

    4 Retweets

    21 Likes

    5 Bookmarks

    0 Replies

    0 Quotes