TP-Link: smuggling malicious code through a security hole in routers
Summary
In 2022 researchers from the Vietnamese telecommunications group Viettel found a buffer overflow in the web-based ping tool of the low-cost TP-Link TL-WR841N Wi-Fi router (CVE-2022-30024). Logged-in attackers could execute their own code via an overlong host address and, for example, install a backdoor. TP-Link delivered updates for revisions V10 to V12 and declared older devices end-of-life.
Ideas
- Diagnostic tools in the web interface are a common entry point for code execution.
- Overlong input overflows the firmware’s internal buffers.
- The required login lowers the risk but does not prevent botnet combinations.
- Older hardware revisions of the same model received no fix.
Insights
- With routers, the same model name says little about support status; the revision is what matters.
- Cheap mass-market routers are attractive botnet building blocks because they are so widespread.
Facts
- The hole has a CVSS score of 8.8.
- Fixed firmware appeared as V10_200325, V11_211209 and V12_220802.
References
Critique
- The report does not say whether default passwords make the required login trivial in practice.
Recommendations
- Check the hardware revision on the type plate before searching for firmware updates.
- Replace routers whose revision no longer receives security updates, or install OpenWrt.
Links to the original source and the Web Archive open in a new tab.