Loading HuntDB...

GHSA-xhjf-xjwg-rm34

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details

In TP-Link Omada er605 1.0.1 through (v2.6) 2.2.3, a cloud-brd binary is susceptible to an integer overflow that leads to a heap-based buffer overflow. After heap shaping, an attacker can achieve code execution in the context of the cloud-brd binary that runs at the root level. This is fixed in ER605(UN)_v2_2.2.4 Build 020240119.

Related CVEs

Key Information

GHSA ID
GHSA-xhjf-xjwg-rm34
Published
March 14, 2024 6:30 PM
Last Modified
August 5, 2024 3:30 PM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 10, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.