peter bassill · operator
$ cve CVE-2024-12344 JSON

CVE-2024-12344 EXPLOIT

6.3
MEDIUM · CVSS 3.1 · EPSS 1.9% (pctl 79)

Patch early

A public exploit exists.

Description

A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Scoring

CVSS6.3 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
EPSS1.87% — more likely to be exploited than 79% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2024-12-08
Last modified2026-06-17

Affected (2)

VendorProduct
tp-linkvn020 f3v
tp-linkvn020 f3v firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD