CVE-2020-28877

Summary

CVECVE-2020-28877
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2020-11-20 16:15:00 UTC
Updated2020-12-03 17:29:00 UTC
DescriptionBuffer overflow in in the copy_msg_element function for the devDiscoverHandle server in the TP-Link WR and WDR series, including WDR7400, WDR7500, WDR7660, WDR7800, WDR8400, WDR8500, WDR8600, WDR8620, WDR8640, WDR8660, WR880N, WR886N, WR890N, WR890N, WR882N, and WR708N.

Risk And Classification

Problem Types: CWE-120

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Tp-link Wdr7400 - All All All
Hardware Tp-link Wdr7400 - All All All
Operating System Tp-link Wdr7400 Firmware - All All All
Operating System Tp-link Wdr7400 Firmware - All All All
Hardware Tp-link Wdr7500 - All All All
Hardware Tp-link Wdr7500 - All All All
Operating System Tp-link Wdr7500 Firmware - All All All
Operating System Tp-link Wdr7500 Firmware - All All All
Hardware Tp-link Wdr7660 - All All All
Hardware Tp-link Wdr7660 - All All All
Operating System Tp-link Wdr7660 Firmware - All All All
Operating System Tp-link Wdr7660 Firmware - All All All
Hardware Tp-link Wdr7800 - All All All
Hardware Tp-link Wdr7800 - All All All
Operating System Tp-link Wdr7800 Firmware - All All All
Operating System Tp-link Wdr7800 Firmware - All All All
Hardware Tp-link Wdr8400 - All All All
Hardware Tp-link Wdr8400 - All All All
Operating System Tp-link Wdr8400 Firmware - All All All
Operating System Tp-link Wdr8400 Firmware - All All All
Hardware Tp-link Wdr8500 - All All All
Hardware Tp-link Wdr8500 - All All All
Operating System Tp-link Wdr8500 Firmware - All All All
Operating System Tp-link Wdr8500 Firmware - All All All
Hardware Tp-link Wdr8600 - All All All
Hardware Tp-link Wdr8600 - All All All
Operating System Tp-link Wdr8600 Firmware - All All All
Operating System Tp-link Wdr8600 Firmware - All All All
Hardware Tp-link Wdr8620 - All All All
Hardware Tp-link Wdr8620 - All All All
Operating System Tp-link Wdr8620 Firmware - All All All
Operating System Tp-link Wdr8620 Firmware - All All All
Hardware Tp-link Wdr8640 - All All All
Hardware Tp-link Wdr8640 - All All All
Operating System Tp-link Wdr8640 Firmware - All All All
Operating System Tp-link Wdr8640 Firmware - All All All
Hardware Tp-link Wdr8660 - All All All
Hardware Tp-link Wdr8660 - All All All
Operating System Tp-link Wdr8660 Firmware - All All All
Operating System Tp-link Wdr8660 Firmware - All All All
Hardware Tp-link Wr708n - All All All
Hardware Tp-link Wr708n - All All All
Operating System Tp-link Wr708n Firmware - All All All
Operating System Tp-link Wr708n Firmware - All All All
Hardware Tp-link Wr880n - All All All
Hardware Tp-link Wr880n - All All All
Operating System Tp-link Wr880n Firmware - All All All
Operating System Tp-link Wr880n Firmware - All All All
Hardware Tp-link Wr882n - All All All
Hardware Tp-link Wr882n - All All All
Operating System Tp-link Wr882n Firmware - All All All
Operating System Tp-link Wr882n Firmware - All All All
Hardware Tp-link Wr886n - All All All
Hardware Tp-link Wr886n - All All All
Operating System Tp-link Wr886n Firmware - All All All
Operating System Tp-link Wr886n Firmware - All All All
Hardware Tp-link Wr890n - All All All
Hardware Tp-link Wr890n - All All All
Operating System Tp-link Wr890n Firmware - All All All
Operating System Tp-link Wr890n Firmware - All All All

References

ReferenceSourceLinkTags
GitHub - peanuts62/TP-Link-poc MISC github.com Broken Link
IBM X-Force Exchange MISC exchange.xforce.ibmcloud.com Third Party Advisory
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

© CVE.report 2026

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

Free CVE JSON API cve.report/api

CVE.report and Source URL Uptime Status status.cve.report