HIGH

CVE-2020-8423

CVSS v3

7.2

HIGH

EPSS Score

30.2%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.

Technical details

Published
4/2/2020

Frequently asked questions

What is CVE-2020-8423?

A buffer overflow in the httpd daemon on TP-Link TL-WR841N V10 (firmware version 3.16.9) devices allows an authenticated remote attacker to execute arbitrary code via a GET request to the page for the configuration of the Wi-Fi network.

Is CVE-2020-8423 actively exploited?

Active exploitation of CVE-2020-8423 has not been confirmed. The EPSS score is 30.2%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2020-8423?

CVE-2020-8423 has a CVSS v3 base score of 7.2 (HIGH severity).

Is CVE-2020-8423 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.