{"id":"CVE-2022-30024","title":"A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network","summary":"A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. T…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-120"],"vendor":"tp-link","product":"tl-wr841_firmware","affected":["tl-wr841_firmware","tl-wr841n_firmware = 3.16.9","tl-wr841n(eu)_firmware = 160325","tl-wr841n_firmware = 150616","tl-wr841n_firmware = 150310"],"published":"2022-07-14","updated":"2026-07-05","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-30024","references":[{"url":"https://pastebin.com/0XRFr3zE","label":"cve@mitre.org"},{"url":"http://tl-wr841.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"http://tp-link.com","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://pastebin.com/0XRFr3zE","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","exploit-available"],"epss":0.02065,"epssPercentile":0.80532,"ingestedAt":"2026-07-06T17:03:24.847Z","exploits":{"github":1,"githubRepos":["https://github.com/ilizavr/CVE-2022-30024"],"checkedAt":"2026-09-23T07:13:23.221Z"},"exploitAvailable":true,"slug":"CVE-2022-30024","body":"## Overview\n\nA buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.\n\n## Affected\n\n- `tl-wr841_firmware`\n- `tl-wr841n_firmware = 3.16.9`\n- `tl-wr841n(eu)_firmware = 160325`\n- `tl-wr841n_firmware = 150616`\n- `tl-wr841n_firmware = 150310`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"midnight","depthScore":61,"depthScoreParts":{"impact":48.4,"likelihood":0.4,"exploitation":12,"ransomware":0},"changes":[{"seq":4621,"id":"CVE-2022-30024","ts":1788887194274,"field":"exploit_available","old":"false","new":"true"},{"seq":3504,"id":"CVE-2022-30024","ts":1788886310746,"field":"exploit_available","old":"true","new":"false"},{"seq":2358,"id":"CVE-2022-30024","ts":1788882980194,"field":"exploit_available","old":"false","new":"true"},{"seq":1387,"id":"CVE-2022-30024","ts":1788882392843,"field":"exploit_available","old":"true","new":"false"},{"seq":501,"id":"CVE-2022-30024","ts":1788881828697,"field":"exploit_available","old":"false","new":"true"}]}