CVE-2022-4498 is a critical heap overflow vulnerability affecting TP-Link Archer C5 and WR710N-V1 routers, allowing a crafted HTTP Basic Authentication packet to cause a denial of service or arbitrary code execution. With a CVSS score of 9.8, this vulnerability is network-exploitable with low complexity, requiring no user interaction or privileges. While no public exploit code or active exploitation has been confirmed, its high severity and potential for remote code execution warrant immediate attention. Community discussion and media coverage indicate some awareness, but it is not currently on CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2_160201_usCPE matchmatch criteria | cpe:2.3:o:tp-link:archer_c5_firmware:2_160201_us:*:*:*:*:*:*:* | ||
1_151022_usCPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wr710n_firmware:1_151022_us:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.