---
id: CVE-2022-30024
title: >-
  A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware
  version 3.16.9) devices allows an authenticated remote attacker to execute
  arbitrary code via a GET request to the page for the System Tools of the Wi-Fi
  network
summary: >-
  A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware
  version 3.16.9) devices allows an authenticated remote attacker to execute
  arbitrary code via a GET request to the page for the System Tools of the Wi-Fi
  network. T…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-120
vendor: tp-link
product: tl-wr841_firmware
affected:
  - tl-wr841_firmware
  - tl-wr841n_firmware = 3.16.9
  - tl-wr841n(eu)_firmware = 160325
  - tl-wr841n_firmware = 150616
  - tl-wr841n_firmware = 150310
published: '2022-07-14'
updated: '2026-07-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-30024'
references:
  - url: 'https://pastebin.com/0XRFr3zE'
    label: cve@mitre.org
  - url: 'http://tl-wr841.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'http://tp-link.com'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://pastebin.com/0XRFr3zE'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02065
epssPercentile: 0.80539
ingestedAt: '2026-07-06T17:03:24.847Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/ilizavr/CVE-2022-30024'
  checkedAt: '2026-09-25T08:20:40.620Z'
exploitAvailable: true
---

## Overview

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V12 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the System Tools of the Wi-Fi network. This affects TL-WR841 V12 TL-WR841N(EU)_V12_160624 and TL-WR841 V11 TL-WR841N(EU)_V11_160325 , TL-WR841N_V11_150616 and TL-WR841 V10 TL-WR841N_V10_150310 are also affected.

## Affected

- `tl-wr841_firmware`
- `tl-wr841n_firmware = 3.16.9`
- `tl-wr841n(eu)_firmware = 160325`
- `tl-wr841n_firmware = 150616`
- `tl-wr841n_firmware = 150310`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
