CVE-2022-24972 is a network-adjacent information disclosure vulnerability affecting TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers, stemming from improper access control in the httpd service. This flaw allows unauthenticated attackers to disclose sensitive information, including stored credentials. With a CVSS score of 6.5 (Medium), it requires network access but no user interaction, leading to high confidentiality impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.20.1CPE matchmatch criteria | cpe:2.3:o:tp-link:tl-wr940n_firmware:3.20.1:build_200316:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.