CVE-2022-24355
About
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of file name extensions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of root. Was ZDI-CAN-13910.
Rainforest analyst review
The TP-Link TL-WR940N router has a stack-based buffer overflow in how it parses file-name extensions: user-supplied data is copied into a fixed-length stack buffer without a length check, and network-adjacent attackers can exploit it — with no authentication — to execute code as root. This is full compromise of the router from a position on the same network segment, no credentials needed, courtesy of a classic missing-bounds-check overflow.
The scoping detail that matters is "network-adjacent": this isn't internet-wide scanning, it's an attacker who is already on the local network (a guest, a compromised device, someone on the same Wi-Fi) turning that adjacency into root on the gateway. That's a very realistic escalation in shared or lightly-segmented environments, and root on the router means traffic interception, DNS tampering, and persistence outside host defenses. The ZDI pedigree indicates a concretely analyzed, weaponizable flaw rather than a theoretical one, so where the precondition is met it's serious.
Our angle is adjacency and segmentation, since the exploit requires local reach. We'd identify any TL-WR940N on the specified build, treat any that serve untrusted or guest networks as high-priority, and pursue firmware updates while ensuring these consumer-grade devices aren't bridging trusted and untrusted segments. Where updates aren't available, the practical control is limiting who shares a network with the device — cutting the adjacency is what neutralizes an attack that can't happen remotely.
References
Related CVEs
Frequently asked questions
What is CVE-2022-24355?
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link TL-WR940N 3.20.1 Build 200316 Rel.34392n (5553) routers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of file name extensions.
How severe is CVE-2022-24355?
CVE-2022-24355 carries a CVSS 3.1 base score of 8.8, rated high. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 88 out of 100, in the critical band.
How is CVE-2022-24355 exploited?
According to the CVSS vector (CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Adjacent, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-24355?
Public advisories list the following as affected: tl-wr940n, tl-wr940n firmware. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-24355?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
