CVE-2024-12344 EXPLOIT
6.3
MEDIUM · CVSS 3.1 · EPSS 1.9% (pctl 79)
Patch early
A public exploit exists.
Description
A vulnerability, which was classified as critical, was found in TP-Link VN020 F3v(T) TT_V6.2.1021. This affects an unknown part of the component FTP USER Command Handler. The manipulation leads to memory corruption. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.
Scoring
| CVSS | 6.3 (MEDIUM, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L |
| EPSS | 1.87% — more likely to be exploited than 79% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2024-12-08 |
| Last modified | 2026-06-17 |
Affected (2)
| Vendor | Product |
|---|---|
| tp-link | vn020 f3v |
| tp-link | vn020 f3v firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | TP-Link VN020 F3v(T) TT_V6.2.1021 - Buffer Overflow Memory Corruption | 2025-04-17 |
References
→ the Explorer · watch your stack · NVD