VYPR

Omada ER605

by TP-Link

CVEs (8)

  • CVE-2024-25139CriMar 14, 2024
    risk 0.65cvss 10.0epss 0.01

    In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level.…

  • CVE-2024-1179HigApr 1, 2024
    risk 0.57cvss 8.8epss 0.01

    TP-Link Omada ER605 DHCPv6 Client Options Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to…

  • CVE-2024-1180HigApr 3, 2024
    risk 0.52cvss 8.0epss 0.01

    TP-Link Omada ER605 Access Control Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605. Authentication is required to exploit this vulnerability. …

  • CVE-2024-5243HigMay 23, 2024
    risk 0.49cvss 7.5epss 0.01

    TP-Link Omada ER605 Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability.…

  • CVE-2024-5242HigMay 23, 2024
    risk 0.49cvss 7.5epss 0.01

    TP-Link Omada ER605 Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this…

  • CVE-2024-5228HigMay 23, 2024
    risk 0.49cvss 7.5epss 0.01

    TP-Link Omada ER605 Comexe DDNS Response Handling Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not…

  • CVE-2024-5227HigMay 23, 2024
    risk 0.49cvss 7.5epss 0.01

    TP-Link Omada ER605 PPTP VPN username Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this…

  • CVE-2024-5244MedMay 23, 2024
    risk 0.27cvss 4.2epss 0.00

    TP-Link Omada ER605 Reliance on Security Through Obscurity Vulnerability. This vulnerability allows network-adjacent attackers to access or spoof DDNS messages on affected installations of TP-Link Omada ER605 routers. Authentication is not required to exploit this vulnerability.…