{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-30T07:21:14.330","vulnerabilities":[{"cve":{"id":"CVE-2022-4498","sourceIdentifier":"cret@cert.org","published":"2023-01-11T21:15:10.213","lastModified":"2026-06-17T05:21:02.703","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In TP-Link routers, Archer C5 and WR710N-V1, running the latest available code, when receiving HTTP Basic Authentication the httpd service can be sent a crafted packet that causes a heap overflow. This can result in either a DoS (by crashing the httpd process) or an arbitrary code execution."},{"lang":"es","value":"En los routers TP-Link, Archer C5 y WR710N-V1, que ejecutan el último código disponible, al recibir autenticación básica HTTP, se puede enviar al servicio httpd un paquete manipulado que provoca un desbordamiento del almacenamiento dinámico. Esto puede resultar en un DoS (al bloquear el proceso httpd) o en la ejecución de código arbitrario."}],"affected":[{"source":"cret@cert.org","affectedData":[{"vendor":"TP-Link","product":"WR710N","versions":[{"version":"V1-151022","status":"affected"}]},{"vendor":"TP-Link","product":"Archer C5","versions":[{"version":"V2_160221_US","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","baseScore":9.8,"baseSeverity":"CRITICAL","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-04-09T14:14:59.035196Z","id":"CVE-2022-4498","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-787"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:archer_c5_firmware:2_160201_us:*:*:*:*:*:*:*","matchCriteriaId":"B7CD0ED5-31F0-47CD-AC06-FA1909722F91"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:archer_c5:2.0:*:*:*:*:*:*:*","matchCriteriaId":"1FE42DA9-9225-4D3F-920E-DD826369FB49"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:tp-link:tl-wr710n_firmware:1_151022_us:*:*:*:*:*:*:*","matchCriteriaId":"343FFD09-AE5D-48F3-A6A9-F28A66D3D49D"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:h:tp-link:tl-wr710n:1.0:*:*:*:*:*:*:*","matchCriteriaId":"0E936B0D-9F70-4F35-A135-6255FA6405DF"}]}]}],"references":[{"url":"https://kb.cert.org/vuls/id/572615","source":"cret@cert.org","tags":["Third Party Advisory","US Government Resource","VDB Entry"]},{"url":"https://kb.cert.org/vuls/id/572615","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","US Government Resource","VDB Entry"]},{"url":"https://www.kb.cert.org/vuls/id/572615","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}