← Vulnerability feed

Vulnerability record · CVE-2022-4296 · published 6 December 2022

CVE-2022-4296: Tp-link tl-wr740n firmware improper resource shutdown vulnerability

Tp Link · Tl Wr740n Firmware

A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.

5.5 CVSS 3.1 Medium EPSS 0.31% · top 78.7% CWE-404 · Improper resource shutdown
5.5CVSS 3.1 base score
0.31%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A vulnerability classified as problematic has been found in TP-Link TL-WR740N. Affected is an unknown function of the component ARP Handler. The manipulation leads to resource consumption. The attack needs to be done within the local network. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-214812.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://vuldb.com/?id.214812 Third Party Advisory
https://www.youtube.com/watch?v=D--fb-cesmA ExploitPermissions RequiredThird Party Advisory
https://vuldb.com/?id.214812 Third Party Advisory
https://www.youtube.com/watch?v=D--fb-cesmA ExploitPermissions RequiredThird Party Advisory

Track CVE-2022-4296 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2023-33538TP-Link router web interface command injection in WlanNetworkRpmTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 contain a command injection flaw in the /userRpm/WlanNetworkRpm component of the route…KEVEPSS 42%analysed7.5CVE-2015-3035TP-Link router directory traversal allows unauthenticated file readA path traversal flaw in the web interface of multiple TP-Link Archer and TL-WR/WDR router models lets a remote attacker read arbitrary files by plac…KEVEPSS 84%analysed6.5CVE-2023-50224TP-Link router httpd authentication bypass exposes stored credentialsThe httpd service on affected TP-Link router firmware contains an improper authentication flaw (CWE-290) that lets a network-adjacent attacker bypass…KEVEPSS 16%analysed8.1CVE-2023-33536Tp-link tl-wr940n firmware out-of-bounds read vulnerabilityTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/WlanMacFilterRp…EPSS 0.90%8.1CVE-2023-33537Tp-link tl-wr940n firmware out-of-bounds read vulnerabilityTP-Link TL-WR940N V2/V4, TL-WR841N V8/V10, and TL-WR740N V1/V2 was discovered to contain a buffer overflow via the component /userRpm/FixMapCfgRpm.EPSS 0.90%7.7CVE-2023-36356Tp-link tl-wr940n firmware out-of-bounds read vulnerabilityTP-Link TL-WR940N V2/V4/V6, TL-WR841N V8, TL-WR941ND V5, and TL-WR740N V1/V2 were discovered to contain a buffer read out-of-bounds via the component…EPSS 0.71%7.5CVE-2023-36354Tp-link tl-wr940n firmware classic buffer overflow vulnerabilityTP-Link TL-WR940N V4, TL-WR841N V8/V10, TL-WR740N V1/V2, TL-WR940N V2/V3, and TL-WR941ND V5/V6 were discovered to contain a buffer overflow in the co…EPSS 0.82%5.0CVE-2014-9350Tp-link tl-wr740n firmware vulnerabilityTP-Link TL-WR740N 4 with firmware 3.17.0 Build 140520, 3.16.6 Build 130529, and 3.16.4 Build 130205 allows remote attackers to cause a denial of serv…EPSS 7.2%

Source: NIST National Vulnerability Database (record CVE-2022-4296), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.