← Back to browse · API

CVE-2024-25139

Severity
CRITICAL
CVSS
10.0
EPSS
0.00877
Risk score
40.31
CISA KEV
No
PoC
No
Published
2024-03-14
Modified
2024-08-05
First seen
2026-08-07
Aliases
EUVD-2024-22487, GHSA-XHJF-XJWG-RM34
Products
n/a:n/a n/a
Sources
euvd EUVD-2024-22487

Description

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

References