CVE-2024-54887
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
09/01/2025
Last modified:
20/06/2025
Description
TP-Link TL-WR940N V3 and V4 with firmware 3.16.9 and earlier contain a buffer overflow via the dnsserver1 and dnsserver2 parameters at /userRpm/Wan6to4TunnelCfgRpm.htm. This vulnerability allows an authenticated attacker to execute arbitrary code on the remote device in the context of the root user.
Impact
Base Score 3.x
8.00
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:tp-link:tl-wr940n_firmware:*:*:*:*:*:*:*:* | 3.16.9 (including) | |
| cpe:2.3:h:tp-link:tl-wr940n:v3:*:*:*:*:*:*:* | ||
| cpe:2.3:h:tp-link:tl-wr940n:v4:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



