← Back to browse · API

CVE-2022-4498

Severity
CRITICAL
CVSS
9.8
EPSS
0.01781
Risk score
39.82
CISA KEV
No
PoC
No
Published
2023-01-11
Modified
2025-11-04
First seen
2026-08-07
Aliases
EUVD-2022-51839, GHSA-8JPC-XWJW-7JCX
Products
TP-Link:Archer C5 V2_160221_US, TP-Link:WR710N V1-151022
Sources
euvd EUVD-2022-51839

Description

In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution.

References